From cb0de450734a139f29a38e86b2daac12a5ea541c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 31 Jan 2024 12:31:50 +0000 Subject: [PATCH] Publish Advisories GHSA-2jf4-qrjv-8cx6 GHSA-3rjg-ff6r-x2c7 GHSA-5mwr-c944-45q4 GHSA-682j-m7jh-pj2w GHSA-7hrr-5mgf-rf3v GHSA-hcj6-8f5v-24x9 GHSA-hgqh-qj43-xfmf GHSA-jgqm-9prw-2qr6 --- .../GHSA-2jf4-qrjv-8cx6.json | 38 +++++++++++++++ .../GHSA-3rjg-ff6r-x2c7.json | 46 +++++++++++++++++++ .../GHSA-5mwr-c944-45q4.json | 38 +++++++++++++++ .../GHSA-682j-m7jh-pj2w.json | 38 +++++++++++++++ .../GHSA-7hrr-5mgf-rf3v.json | 46 +++++++++++++++++++ .../GHSA-hcj6-8f5v-24x9.json | 38 +++++++++++++++ .../GHSA-hgqh-qj43-xfmf.json | 38 +++++++++++++++ .../GHSA-jgqm-9prw-2qr6.json | 38 +++++++++++++++ 8 files changed, 320 insertions(+) create mode 100644 advisories/unreviewed/2024/01/GHSA-2jf4-qrjv-8cx6/GHSA-2jf4-qrjv-8cx6.json create mode 100644 advisories/unreviewed/2024/01/GHSA-3rjg-ff6r-x2c7/GHSA-3rjg-ff6r-x2c7.json create mode 100644 advisories/unreviewed/2024/01/GHSA-5mwr-c944-45q4/GHSA-5mwr-c944-45q4.json create mode 100644 advisories/unreviewed/2024/01/GHSA-682j-m7jh-pj2w/GHSA-682j-m7jh-pj2w.json create mode 100644 advisories/unreviewed/2024/01/GHSA-7hrr-5mgf-rf3v/GHSA-7hrr-5mgf-rf3v.json create mode 100644 advisories/unreviewed/2024/01/GHSA-hcj6-8f5v-24x9/GHSA-hcj6-8f5v-24x9.json create mode 100644 advisories/unreviewed/2024/01/GHSA-hgqh-qj43-xfmf/GHSA-hgqh-qj43-xfmf.json create mode 100644 advisories/unreviewed/2024/01/GHSA-jgqm-9prw-2qr6/GHSA-jgqm-9prw-2qr6.json diff --git a/advisories/unreviewed/2024/01/GHSA-2jf4-qrjv-8cx6/GHSA-2jf4-qrjv-8cx6.json b/advisories/unreviewed/2024/01/GHSA-2jf4-qrjv-8cx6/GHSA-2jf4-qrjv-8cx6.json new file mode 100644 index 00000000000..935f852474b --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2jf4-qrjv-8cx6/GHSA-2jf4-qrjv-8cx6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jf4-qrjv-8cx6", + "modified": "2024-01-31T12:30:18Z", + "published": "2024-01-31T12:30:18Z", + "aliases": [ + "CVE-2024-22305" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in ali Forms Contact Form builder with drag & drop for WordPress – Kali Forms.This issue affects Contact Form builder with drag & drop for WordPress – Kali Forms: from n/a through 2.3.36.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22305" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/kali-forms/wordpress-kali-forms-plugin-2-3-38-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T12:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-3rjg-ff6r-x2c7/GHSA-3rjg-ff6r-x2c7.json b/advisories/unreviewed/2024/01/GHSA-3rjg-ff6r-x2c7/GHSA-3rjg-ff6r-x2c7.json new file mode 100644 index 00000000000..ba3074d3335 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-3rjg-ff6r-x2c7/GHSA-3rjg-ff6r-x2c7.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rjg-ff6r-x2c7", + "modified": "2024-01-31T12:30:17Z", + "published": "2024-01-31T12:30:17Z", + "aliases": [ + "CVE-2024-1099" + ], + "details": "A vulnerability was found in Rebuild up to 3.5.5. It has been classified as problematic. Affected is the function getFileOfData of the file /filex/read-raw. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252456.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1099" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252456" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252456" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/mailemonyeyongjuan/tha8tr/dcilugg0htp973nx" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T12:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-5mwr-c944-45q4/GHSA-5mwr-c944-45q4.json b/advisories/unreviewed/2024/01/GHSA-5mwr-c944-45q4/GHSA-5mwr-c944-45q4.json new file mode 100644 index 00000000000..91fbca5ae16 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-5mwr-c944-45q4/GHSA-5mwr-c944-45q4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mwr-c944-45q4", + "modified": "2024-01-31T12:30:17Z", + "published": "2024-01-31T12:30:17Z", + "aliases": [ + "CVE-2024-22287" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Luděk Melichar Better Anchor Links allows Cross-Site Scripting (XSS).This issue affects Better Anchor Links: from n/a through 1.7.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22287" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/better-anchor-links/wordpress-better-anchor-links-plugin-1-7-5-csrf-to-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T12:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-682j-m7jh-pj2w/GHSA-682j-m7jh-pj2w.json b/advisories/unreviewed/2024/01/GHSA-682j-m7jh-pj2w/GHSA-682j-m7jh-pj2w.json new file mode 100644 index 00000000000..64f08fd3f69 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-682j-m7jh-pj2w/GHSA-682j-m7jh-pj2w.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-682j-m7jh-pj2w", + "modified": "2024-01-31T12:30:17Z", + "published": "2024-01-31T12:30:17Z", + "aliases": [ + "CVE-2023-50357" + ], + "details": "A cross site scripting vulnerability in the AREAL SAS Websrv1 ASP website allows a remote low-privileged attacker to gain escalated privileges of other non-admin users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50357" + }, + { + "type": "WEB", + "url": "https://www.areal-topkapi.com/en/services/security-bulletins" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-7hrr-5mgf-rf3v/GHSA-7hrr-5mgf-rf3v.json b/advisories/unreviewed/2024/01/GHSA-7hrr-5mgf-rf3v/GHSA-7hrr-5mgf-rf3v.json new file mode 100644 index 00000000000..e67406434cb --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-7hrr-5mgf-rf3v/GHSA-7hrr-5mgf-rf3v.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hrr-5mgf-rf3v", + "modified": "2024-01-31T12:30:17Z", + "published": "2024-01-31T12:30:17Z", + "aliases": [ + "CVE-2024-1098" + ], + "details": "A vulnerability was found in Rebuild up to 3.5.5 and classified as problematic. This issue affects the function QiniuCloud.getStorageFile of the file /filex/proxy-download. The manipulation of the argument url leads to information disclosure. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252455.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1098" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.252455" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.252455" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/mailemonyeyongjuan/tha8tr/ouiw375l0m8mw5ls" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T12:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-hcj6-8f5v-24x9/GHSA-hcj6-8f5v-24x9.json b/advisories/unreviewed/2024/01/GHSA-hcj6-8f5v-24x9/GHSA-hcj6-8f5v-24x9.json new file mode 100644 index 00000000000..04e233198f1 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-hcj6-8f5v-24x9/GHSA-hcj6-8f5v-24x9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcj6-8f5v-24x9", + "modified": "2024-01-31T12:30:17Z", + "published": "2024-01-31T12:30:17Z", + "aliases": [ + "CVE-2024-22290" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in AboZain,O7abeeb,UnitOne Custom Dashboard Widgets allows Cross-Site Scripting (XSS).This issue affects Custom Dashboard Widgets: from n/a through 1.3.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22290" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/custom-dashboard-widgets/wordpress-custom-dashboard-widgets-plugin-1-3-1-csrf-to-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T12:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-hgqh-qj43-xfmf/GHSA-hgqh-qj43-xfmf.json b/advisories/unreviewed/2024/01/GHSA-hgqh-qj43-xfmf/GHSA-hgqh-qj43-xfmf.json new file mode 100644 index 00000000000..fbb2d78a597 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-hgqh-qj43-xfmf/GHSA-hgqh-qj43-xfmf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgqh-qj43-xfmf", + "modified": "2024-01-31T12:30:17Z", + "published": "2024-01-31T12:30:17Z", + "aliases": [ + "CVE-2023-50356" + ], + "details": "SSL connections to NOVELL and Synology LDAP server are vulnerable to a man-in-the-middle attack due to improper certificate validation in AREAL Topkapi Vision (Server). This allows a remote unauthenticated attacker to gather sensitive information and prevent valid users from login.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50356" + }, + { + "type": "WEB", + "url": "https://www.areal-topkapi.com/en/services/security-bulletins" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T11:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-jgqm-9prw-2qr6/GHSA-jgqm-9prw-2qr6.json b/advisories/unreviewed/2024/01/GHSA-jgqm-9prw-2qr6/GHSA-jgqm-9prw-2qr6.json new file mode 100644 index 00000000000..d7ef661ec84 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-jgqm-9prw-2qr6/GHSA-jgqm-9prw-2qr6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgqm-9prw-2qr6", + "modified": "2024-01-31T12:30:18Z", + "published": "2024-01-31T12:30:18Z", + "aliases": [ + "CVE-2024-23507" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InstaWP Team InstaWP Connect – 1-click WP Staging & Migration.This issue affects InstaWP Connect – 1-click WP Staging & Migration: from n/a through 0.1.0.9.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23507" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/instawp-connect/wordpress-instawp-connect-plugin-0-1-0-9-sql-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-31T12:16:06Z" + } +} \ No newline at end of file