Publish Advisories

GHSA-2jf4-qrjv-8cx6
GHSA-3rjg-ff6r-x2c7
GHSA-5mwr-c944-45q4
GHSA-682j-m7jh-pj2w
GHSA-7hrr-5mgf-rf3v
GHSA-hcj6-8f5v-24x9
GHSA-hgqh-qj43-xfmf
GHSA-jgqm-9prw-2qr6
This commit is contained in:
advisory-database[bot]
2024-01-31 12:31:50 +00:00
parent 19a327fc1c
commit cb0de45073
8 changed files with 320 additions and 0 deletions
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2jf4-qrjv-8cx6",
"modified": "2024-01-31T12:30:18Z",
"published": "2024-01-31T12:30:18Z",
"aliases": [
"CVE-2024-22305"
],
"details": "Authorization Bypass Through User-Controlled Key vulnerability in ali Forms Contact Form builder with drag & drop for WordPress Kali Forms.This issue affects Contact Form builder with drag & drop for WordPress Kali Forms: from n/a through 2.3.36.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22305"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/kali-forms/wordpress-kali-forms-plugin-2-3-38-insecure-direct-object-references-idor-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-639"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-31T12:16:05Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3rjg-ff6r-x2c7",
"modified": "2024-01-31T12:30:17Z",
"published": "2024-01-31T12:30:17Z",
"aliases": [
"CVE-2024-1099"
],
"details": "A vulnerability was found in Rebuild up to 3.5.5. It has been classified as problematic. Affected is the function getFileOfData of the file /filex/read-raw. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252456.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1099"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.252456"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.252456"
},
{
"type": "WEB",
"url": "https://www.yuque.com/mailemonyeyongjuan/tha8tr/dcilugg0htp973nx"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-31T12:16:04Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5mwr-c944-45q4",
"modified": "2024-01-31T12:30:17Z",
"published": "2024-01-31T12:30:17Z",
"aliases": [
"CVE-2024-22287"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in Luděk Melichar Better Anchor Links allows Cross-Site Scripting (XSS).This issue affects Better Anchor Links: from n/a through 1.7.5.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22287"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/better-anchor-links/wordpress-better-anchor-links-plugin-1-7-5-csrf-to-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-31T12:16:05Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-682j-m7jh-pj2w",
"modified": "2024-01-31T12:30:17Z",
"published": "2024-01-31T12:30:17Z",
"aliases": [
"CVE-2023-50357"
],
"details": "A cross site scripting vulnerability in the AREAL SAS Websrv1 ASP website allows a remote low-privileged attacker to gain escalated privileges of other non-admin users.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50357"
},
{
"type": "WEB",
"url": "https://www.areal-topkapi.com/en/services/security-bulletins"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-31T11:15:08Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7hrr-5mgf-rf3v",
"modified": "2024-01-31T12:30:17Z",
"published": "2024-01-31T12:30:17Z",
"aliases": [
"CVE-2024-1098"
],
"details": "A vulnerability was found in Rebuild up to 3.5.5 and classified as problematic. This issue affects the function QiniuCloud.getStorageFile of the file /filex/proxy-download. The manipulation of the argument url leads to information disclosure. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252455.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1098"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.252455"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.252455"
},
{
"type": "WEB",
"url": "https://www.yuque.com/mailemonyeyongjuan/tha8tr/ouiw375l0m8mw5ls"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-31T12:16:04Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hcj6-8f5v-24x9",
"modified": "2024-01-31T12:30:17Z",
"published": "2024-01-31T12:30:17Z",
"aliases": [
"CVE-2024-22290"
],
"details": "Cross-Site Request Forgery (CSRF) vulnerability in AboZain,O7abeeb,UnitOne Custom Dashboard Widgets allows Cross-Site Scripting (XSS).This issue affects Custom Dashboard Widgets: from n/a through 1.3.1.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22290"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/custom-dashboard-widgets/wordpress-custom-dashboard-widgets-plugin-1-3-1-csrf-to-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-31T12:16:05Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hgqh-qj43-xfmf",
"modified": "2024-01-31T12:30:17Z",
"published": "2024-01-31T12:30:17Z",
"aliases": [
"CVE-2023-50356"
],
"details": "SSL connections to NOVELL and Synology LDAP server are vulnerable to a man-in-the-middle attack due to improper certificate validation in AREAL Topkapi Vision (Server). This allows a remote unauthenticated attacker to gather sensitive information and prevent valid users from login.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50356"
},
{
"type": "WEB",
"url": "https://www.areal-topkapi.com/en/services/security-bulletins"
}
],
"database_specific": {
"cwe_ids": [
"CWE-295"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-31T11:15:07Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jgqm-9prw-2qr6",
"modified": "2024-01-31T12:30:18Z",
"published": "2024-01-31T12:30:18Z",
"aliases": [
"CVE-2024-23507"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InstaWP Team InstaWP Connect 1-click WP Staging & Migration.This issue affects InstaWP Connect 1-click WP Staging & Migration: from n/a through 0.1.0.9.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23507"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/instawp-connect/wordpress-instawp-connect-plugin-0-1-0-9-sql-injection-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-31T12:16:06Z"
}
}