From cbad1aa07f7b6cf3a6a5e58ab6bdb73faeae6f43 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 12 May 2023 18:31:56 +0000 Subject: [PATCH] Publish Advisories GHSA-5mwm-wccq-xqcp GHSA-2mxf-g57h-fggq GHSA-3mp3-p7xf-v5f6 GHSA-434x-65h3-cg6q GHSA-46qf-g7mj-p34v GHSA-4frm-cwqq-w26g GHSA-5mxr-j6vv-8p4c GHSA-5rv6-mg5f-h55g GHSA-734f-vhpg-wrgp GHSA-76rv-vcjw-7q23 GHSA-cgqm-2q6p-33gm GHSA-f56m-69v4-8288 GHSA-h4w6-443w-q3c4 GHSA-h6jm-ghq6-38cg GHSA-hm93-fhwx-7mmj GHSA-mm96-9vx8-pfhj GHSA-p36v-2c7w-2x8f GHSA-p9jh-4px8-qm49 GHSA-pwqv-pfwc-3854 GHSA-qpwc-q7rm-3jjq GHSA-rhqm-jg9x-wp83 GHSA-wmhj-jq93-j3p7 GHSA-xgf4-6mjg-7hqq --- .../GHSA-5mwm-wccq-xqcp.json | 4 ++ .../GHSA-2mxf-g57h-fggq.json | 9 ++-- .../GHSA-3mp3-p7xf-v5f6.json | 9 ++-- .../GHSA-434x-65h3-cg6q.json | 39 +++++++++++++++++ .../GHSA-46qf-g7mj-p34v.json | 9 ++-- .../GHSA-4frm-cwqq-w26g.json | 9 ++-- .../GHSA-5mxr-j6vv-8p4c.json | 9 ++-- .../GHSA-5rv6-mg5f-h55g.json | 7 ++- .../GHSA-734f-vhpg-wrgp.json | 9 ++-- .../GHSA-76rv-vcjw-7q23.json | 39 +++++++++++++++++ .../GHSA-cgqm-2q6p-33gm.json | 42 ++++++++++++++++++ .../GHSA-f56m-69v4-8288.json | 9 ++-- .../GHSA-h4w6-443w-q3c4.json | 35 +++++++++++++++ .../GHSA-h6jm-ghq6-38cg.json | 9 ++-- .../GHSA-hm93-fhwx-7mmj.json | 43 +++++++++++++++++++ .../GHSA-mm96-9vx8-pfhj.json | 9 ++-- .../GHSA-p36v-2c7w-2x8f.json | 39 +++++++++++++++++ .../GHSA-p9jh-4px8-qm49.json | 9 ++-- .../GHSA-pwqv-pfwc-3854.json | 2 +- .../GHSA-qpwc-q7rm-3jjq.json | 9 ++-- .../GHSA-rhqm-jg9x-wp83.json | 9 ++-- .../GHSA-wmhj-jq93-j3p7.json | 9 ++-- .../GHSA-xgf4-6mjg-7hqq.json | 2 +- 23 files changed, 326 insertions(+), 43 deletions(-) create mode 100644 advisories/unreviewed/2023/05/GHSA-434x-65h3-cg6q/GHSA-434x-65h3-cg6q.json create mode 100644 advisories/unreviewed/2023/05/GHSA-76rv-vcjw-7q23/GHSA-76rv-vcjw-7q23.json create mode 100644 advisories/unreviewed/2023/05/GHSA-cgqm-2q6p-33gm/GHSA-cgqm-2q6p-33gm.json create mode 100644 advisories/unreviewed/2023/05/GHSA-h4w6-443w-q3c4/GHSA-h4w6-443w-q3c4.json create mode 100644 advisories/unreviewed/2023/05/GHSA-hm93-fhwx-7mmj/GHSA-hm93-fhwx-7mmj.json create mode 100644 advisories/unreviewed/2023/05/GHSA-p36v-2c7w-2x8f/GHSA-p36v-2c7w-2x8f.json diff --git a/advisories/unreviewed/2023/04/GHSA-5mwm-wccq-xqcp/GHSA-5mwm-wccq-xqcp.json b/advisories/unreviewed/2023/04/GHSA-5mwm-wccq-xqcp/GHSA-5mwm-wccq-xqcp.json index 9ce4e6f6ef4..0b510467790 100644 --- a/advisories/unreviewed/2023/04/GHSA-5mwm-wccq-xqcp/GHSA-5mwm-wccq-xqcp.json +++ b/advisories/unreviewed/2023/04/GHSA-5mwm-wccq-xqcp/GHSA-5mwm-wccq-xqcp.json @@ -25,6 +25,10 @@ "type": "WEB", "url": "https://github.com/python/cpython/issues/102988" }, + { + "type": "WEB", + "url": "https://python-security.readthedocs.io/vuln/email-parseaddr-realname.html" + }, { "type": "WEB", "url": "http://python.com" diff --git a/advisories/unreviewed/2023/05/GHSA-2mxf-g57h-fggq/GHSA-2mxf-g57h-fggq.json b/advisories/unreviewed/2023/05/GHSA-2mxf-g57h-fggq/GHSA-2mxf-g57h-fggq.json index c17db3a3a11..b634155148f 100644 --- a/advisories/unreviewed/2023/05/GHSA-2mxf-g57h-fggq/GHSA-2mxf-g57h-fggq.json +++ b/advisories/unreviewed/2023/05/GHSA-2mxf-g57h-fggq/GHSA-2mxf-g57h-fggq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2mxf-g57h-fggq", - "modified": "2023-05-09T03:30:40Z", + "modified": "2023-05-12T18:30:25Z", "published": "2023-05-09T03:30:40Z", "aliases": [ "CVE-2022-47490" ], "details": "In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-3mp3-p7xf-v5f6/GHSA-3mp3-p7xf-v5f6.json b/advisories/unreviewed/2023/05/GHSA-3mp3-p7xf-v5f6/GHSA-3mp3-p7xf-v5f6.json index 3bcc0470d3e..498fff72872 100644 --- a/advisories/unreviewed/2023/05/GHSA-3mp3-p7xf-v5f6/GHSA-3mp3-p7xf-v5f6.json +++ b/advisories/unreviewed/2023/05/GHSA-3mp3-p7xf-v5f6/GHSA-3mp3-p7xf-v5f6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3mp3-p7xf-v5f6", - "modified": "2023-05-04T21:30:29Z", + "modified": "2023-05-12T18:30:23Z", "published": "2023-05-04T21:30:29Z", "aliases": [ "CVE-2023-25289" ], "details": "Directory Traversal vulnerability in virtualreception Digital Receptie version win7sp1_rtm.101119-1850 6.1.7601.1.0.65792 in embedded web server, allows attacker to gain sensitive information via a crafted GET request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-434x-65h3-cg6q/GHSA-434x-65h3-cg6q.json b/advisories/unreviewed/2023/05/GHSA-434x-65h3-cg6q/GHSA-434x-65h3-cg6q.json new file mode 100644 index 00000000000..a37670a9a43 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-434x-65h3-cg6q/GHSA-434x-65h3-cg6q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-434x-65h3-cg6q", + "modified": "2023-05-12T18:30:25Z", + "published": "2023-05-12T18:30:25Z", + "aliases": [ + "CVE-2023-25428" + ], + "details": "A DLL Hijacking issue discovered in Soft-o Free Password Manager 1.1.20 allows attackers to create arbitrary DLLs leading to code execution.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25428" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/172259/Soft-o-Free-Password-Manager-1.1.20-DLL-Hijacking.html" + }, + { + "type": "WEB", + "url": "https://www.soft-o.com/products/free-password-manager.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-46qf-g7mj-p34v/GHSA-46qf-g7mj-p34v.json b/advisories/unreviewed/2023/05/GHSA-46qf-g7mj-p34v/GHSA-46qf-g7mj-p34v.json index 562eaae2dc1..40f56bde9cd 100644 --- a/advisories/unreviewed/2023/05/GHSA-46qf-g7mj-p34v/GHSA-46qf-g7mj-p34v.json +++ b/advisories/unreviewed/2023/05/GHSA-46qf-g7mj-p34v/GHSA-46qf-g7mj-p34v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-46qf-g7mj-p34v", - "modified": "2023-05-09T03:30:38Z", + "modified": "2023-05-12T18:30:25Z", "published": "2023-05-09T03:30:38Z", "aliases": [ "CVE-2022-38685" ], "details": "In bluetooth service, there is a possible missing permission check. This could lead to local denial of service in bluetooth service with no additional execution privileges needed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-4frm-cwqq-w26g/GHSA-4frm-cwqq-w26g.json b/advisories/unreviewed/2023/05/GHSA-4frm-cwqq-w26g/GHSA-4frm-cwqq-w26g.json index ed03d12f78c..e5830d07f3c 100644 --- a/advisories/unreviewed/2023/05/GHSA-4frm-cwqq-w26g/GHSA-4frm-cwqq-w26g.json +++ b/advisories/unreviewed/2023/05/GHSA-4frm-cwqq-w26g/GHSA-4frm-cwqq-w26g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4frm-cwqq-w26g", - "modified": "2023-05-08T15:30:20Z", + "modified": "2023-05-12T18:30:24Z", "published": "2023-05-08T15:30:20Z", "aliases": [ "CVE-2023-30092" ], "details": "SourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-5mxr-j6vv-8p4c/GHSA-5mxr-j6vv-8p4c.json b/advisories/unreviewed/2023/05/GHSA-5mxr-j6vv-8p4c/GHSA-5mxr-j6vv-8p4c.json index bac0f6e15fe..b0c6e491e3c 100644 --- a/advisories/unreviewed/2023/05/GHSA-5mxr-j6vv-8p4c/GHSA-5mxr-j6vv-8p4c.json +++ b/advisories/unreviewed/2023/05/GHSA-5mxr-j6vv-8p4c/GHSA-5mxr-j6vv-8p4c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5mxr-j6vv-8p4c", - "modified": "2023-05-09T03:30:40Z", + "modified": "2023-05-12T18:30:25Z", "published": "2023-05-09T03:30:40Z", "aliases": [ "CVE-2022-47493" ], "details": "In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-5rv6-mg5f-h55g/GHSA-5rv6-mg5f-h55g.json b/advisories/unreviewed/2023/05/GHSA-5rv6-mg5f-h55g/GHSA-5rv6-mg5f-h55g.json index 0cd1009fad7..a3a5b39c048 100644 --- a/advisories/unreviewed/2023/05/GHSA-5rv6-mg5f-h55g/GHSA-5rv6-mg5f-h55g.json +++ b/advisories/unreviewed/2023/05/GHSA-5rv6-mg5f-h55g/GHSA-5rv6-mg5f-h55g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5rv6-mg5f-h55g", - "modified": "2023-05-06T00:30:16Z", + "modified": "2023-05-12T18:30:24Z", "published": "2023-05-06T00:30:16Z", "aliases": [ "CVE-2023-30065" ], "details": "MitraStar GPT-2741GNAC-N2 with firmware BR_g5.9_1.11(WVK.0)b32 was discovered to contain a remote code execution (RCE) vulnerability in the ping function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/05/GHSA-734f-vhpg-wrgp/GHSA-734f-vhpg-wrgp.json b/advisories/unreviewed/2023/05/GHSA-734f-vhpg-wrgp/GHSA-734f-vhpg-wrgp.json index 9a71d5817f9..2edcc937023 100644 --- a/advisories/unreviewed/2023/05/GHSA-734f-vhpg-wrgp/GHSA-734f-vhpg-wrgp.json +++ b/advisories/unreviewed/2023/05/GHSA-734f-vhpg-wrgp/GHSA-734f-vhpg-wrgp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-734f-vhpg-wrgp", - "modified": "2023-05-08T15:30:18Z", + "modified": "2023-05-12T18:30:24Z", "published": "2023-05-08T15:30:18Z", "aliases": [ "CVE-2020-36065" ], "details": "Cross Site Request Forgery (CSRF) vulnerability in FlyCms 1.0 allows attackers to add arbitrary administrator accounts via system/admin/admin_save.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-76rv-vcjw-7q23/GHSA-76rv-vcjw-7q23.json b/advisories/unreviewed/2023/05/GHSA-76rv-vcjw-7q23/GHSA-76rv-vcjw-7q23.json new file mode 100644 index 00000000000..6a7f9a7c59b --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-76rv-vcjw-7q23/GHSA-76rv-vcjw-7q23.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76rv-vcjw-7q23", + "modified": "2023-05-12T18:30:25Z", + "published": "2023-05-12T18:30:25Z", + "aliases": [ + "CVE-2023-2457" + ], + "details": "Out of bounds write in ChromeOS Audio Server in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker to potentially exploit heap corruption via crafted audio file. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2457" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-chromeos.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1420790" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-cgqm-2q6p-33gm/GHSA-cgqm-2q6p-33gm.json b/advisories/unreviewed/2023/05/GHSA-cgqm-2q6p-33gm/GHSA-cgqm-2q6p-33gm.json new file mode 100644 index 00000000000..4b37caf1143 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-cgqm-2q6p-33gm/GHSA-cgqm-2q6p-33gm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgqm-2q6p-33gm", + "modified": "2023-05-12T18:30:25Z", + "published": "2023-05-12T18:30:25Z", + "aliases": [ + "CVE-2023-25927" + ], + "details": "IBM Security Verify Access 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, and 10.0.5 could allow an attacker to crash the webseald process using specially crafted HTTP requests resulting in loss of access to the system. IBM X-Force ID: 247635.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25927" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/247635" + }, + { + "type": "WEB", + "url": "https://https://www.ibm.com/support/pages/node/6989653" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-f56m-69v4-8288/GHSA-f56m-69v4-8288.json b/advisories/unreviewed/2023/05/GHSA-f56m-69v4-8288/GHSA-f56m-69v4-8288.json index 81066b3a2c1..a9ce7b5071a 100644 --- a/advisories/unreviewed/2023/05/GHSA-f56m-69v4-8288/GHSA-f56m-69v4-8288.json +++ b/advisories/unreviewed/2023/05/GHSA-f56m-69v4-8288/GHSA-f56m-69v4-8288.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f56m-69v4-8288", - "modified": "2023-05-09T03:30:39Z", + "modified": "2023-05-12T18:30:25Z", "published": "2023-05-09T03:30:39Z", "aliases": [ "CVE-2022-47334" ], "details": "In phasecheck server, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-h4w6-443w-q3c4/GHSA-h4w6-443w-q3c4.json b/advisories/unreviewed/2023/05/GHSA-h4w6-443w-q3c4/GHSA-h4w6-443w-q3c4.json new file mode 100644 index 00000000000..23f360fb5c4 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-h4w6-443w-q3c4/GHSA-h4w6-443w-q3c4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4w6-443w-q3c4", + "modified": "2023-05-12T18:30:25Z", + "published": "2023-05-12T18:30:25Z", + "aliases": [ + "CVE-2023-31983" + ], + "details": "A Command Injection vulnerability in Edimax Wireless Router N300 Firmware BR-6428NS_v4 allows attacker to execute arbitrary code via the mp function in /bin/webs without any limitations.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31983" + }, + { + "type": "WEB", + "url": "https://github.com/Erebua/CVE/blob/main/N300_BR-6428nS%20V4/2/Readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-h6jm-ghq6-38cg/GHSA-h6jm-ghq6-38cg.json b/advisories/unreviewed/2023/05/GHSA-h6jm-ghq6-38cg/GHSA-h6jm-ghq6-38cg.json index 71510761872..1c5b812d50d 100644 --- a/advisories/unreviewed/2023/05/GHSA-h6jm-ghq6-38cg/GHSA-h6jm-ghq6-38cg.json +++ b/advisories/unreviewed/2023/05/GHSA-h6jm-ghq6-38cg/GHSA-h6jm-ghq6-38cg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h6jm-ghq6-38cg", - "modified": "2023-05-08T15:30:18Z", + "modified": "2023-05-12T18:30:24Z", "published": "2023-05-08T15:30:18Z", "aliases": [ "CVE-2021-28998" ], "details": "File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-hm93-fhwx-7mmj/GHSA-hm93-fhwx-7mmj.json b/advisories/unreviewed/2023/05/GHSA-hm93-fhwx-7mmj/GHSA-hm93-fhwx-7mmj.json new file mode 100644 index 00000000000..011e0a57818 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-hm93-fhwx-7mmj/GHSA-hm93-fhwx-7mmj.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hm93-fhwx-7mmj", + "modified": "2023-05-12T18:30:25Z", + "published": "2023-05-12T18:30:25Z", + "aliases": [ + "CVE-2022-48020" + ], + "details": "Vinteo VCC v2.36.4 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the conference parameter. This vulnerability allows attackers to inject arbitrary code which will be executed by the victim user's browser.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48020" + }, + { + "type": "WEB", + "url": "https://seq.team/en/" + }, + { + "type": "WEB", + "url": "https://seq.team/en/blog/reflected-cross-site-scripting-xss-in-vinteo-vcc/" + }, + { + "type": "WEB", + "url": "https://www.linkedin.com/in/dmitry-kiryukhin-b5741421b/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-mm96-9vx8-pfhj/GHSA-mm96-9vx8-pfhj.json b/advisories/unreviewed/2023/05/GHSA-mm96-9vx8-pfhj/GHSA-mm96-9vx8-pfhj.json index 0f0e72907e9..5a6705440b7 100644 --- a/advisories/unreviewed/2023/05/GHSA-mm96-9vx8-pfhj/GHSA-mm96-9vx8-pfhj.json +++ b/advisories/unreviewed/2023/05/GHSA-mm96-9vx8-pfhj/GHSA-mm96-9vx8-pfhj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mm96-9vx8-pfhj", - "modified": "2023-05-08T15:30:18Z", + "modified": "2023-05-12T18:30:24Z", "published": "2023-05-08T15:30:18Z", "aliases": [ "CVE-2020-23966" ], "details": "SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /post.php in a crafted GET request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-p36v-2c7w-2x8f/GHSA-p36v-2c7w-2x8f.json b/advisories/unreviewed/2023/05/GHSA-p36v-2c7w-2x8f/GHSA-p36v-2c7w-2x8f.json new file mode 100644 index 00000000000..de402cb8e16 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-p36v-2c7w-2x8f/GHSA-p36v-2c7w-2x8f.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p36v-2c7w-2x8f", + "modified": "2023-05-12T18:30:25Z", + "published": "2023-05-12T18:30:25Z", + "aliases": [ + "CVE-2023-2458" + ], + "details": "Use after free in ChromeOS Camera in Google Chrome on ChromeOS prior to 113.0.5672.114 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via UI interaction. (Chromium security severity: High)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2458" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-chromeos.html" + }, + { + "type": "WEB", + "url": "https://crbug.com/1430692" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-p9jh-4px8-qm49/GHSA-p9jh-4px8-qm49.json b/advisories/unreviewed/2023/05/GHSA-p9jh-4px8-qm49/GHSA-p9jh-4px8-qm49.json index e59695b6100..a4a300a2161 100644 --- a/advisories/unreviewed/2023/05/GHSA-p9jh-4px8-qm49/GHSA-p9jh-4px8-qm49.json +++ b/advisories/unreviewed/2023/05/GHSA-p9jh-4px8-qm49/GHSA-p9jh-4px8-qm49.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p9jh-4px8-qm49", - "modified": "2023-05-09T03:30:40Z", + "modified": "2023-05-12T18:30:25Z", "published": "2023-05-09T03:30:40Z", "aliases": [ "CVE-2022-47492" ], "details": "In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-pwqv-pfwc-3854/GHSA-pwqv-pfwc-3854.json b/advisories/unreviewed/2023/05/GHSA-pwqv-pfwc-3854/GHSA-pwqv-pfwc-3854.json index 7541915633e..4d0ece667e1 100644 --- a/advisories/unreviewed/2023/05/GHSA-pwqv-pfwc-3854/GHSA-pwqv-pfwc-3854.json +++ b/advisories/unreviewed/2023/05/GHSA-pwqv-pfwc-3854/GHSA-pwqv-pfwc-3854.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-qpwc-q7rm-3jjq/GHSA-qpwc-q7rm-3jjq.json b/advisories/unreviewed/2023/05/GHSA-qpwc-q7rm-3jjq/GHSA-qpwc-q7rm-3jjq.json index 4e073d33d16..491296633b2 100644 --- a/advisories/unreviewed/2023/05/GHSA-qpwc-q7rm-3jjq/GHSA-qpwc-q7rm-3jjq.json +++ b/advisories/unreviewed/2023/05/GHSA-qpwc-q7rm-3jjq/GHSA-qpwc-q7rm-3jjq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qpwc-q7rm-3jjq", - "modified": "2023-05-09T03:30:41Z", + "modified": "2023-05-12T18:30:25Z", "published": "2023-05-09T03:30:41Z", "aliases": [ "CVE-2022-48384" ], "details": "In srtd service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-rhqm-jg9x-wp83/GHSA-rhqm-jg9x-wp83.json b/advisories/unreviewed/2023/05/GHSA-rhqm-jg9x-wp83/GHSA-rhqm-jg9x-wp83.json index 29d5dacd695..d5370154140 100644 --- a/advisories/unreviewed/2023/05/GHSA-rhqm-jg9x-wp83/GHSA-rhqm-jg9x-wp83.json +++ b/advisories/unreviewed/2023/05/GHSA-rhqm-jg9x-wp83/GHSA-rhqm-jg9x-wp83.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rhqm-jg9x-wp83", - "modified": "2023-05-04T21:30:30Z", + "modified": "2023-05-12T18:30:24Z", "published": "2023-05-04T21:30:30Z", "aliases": [ "CVE-2023-30399" ], "details": "Insecure permissions in the settings page of GARO Wallbox GLB/GTB/GTC before v189 allows attackers to redirect users to a crafted update package link via a man-in-the-middle attack.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-732" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-wmhj-jq93-j3p7/GHSA-wmhj-jq93-j3p7.json b/advisories/unreviewed/2023/05/GHSA-wmhj-jq93-j3p7/GHSA-wmhj-jq93-j3p7.json index a1875dd7f1c..8bac2281f77 100644 --- a/advisories/unreviewed/2023/05/GHSA-wmhj-jq93-j3p7/GHSA-wmhj-jq93-j3p7.json +++ b/advisories/unreviewed/2023/05/GHSA-wmhj-jq93-j3p7/GHSA-wmhj-jq93-j3p7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wmhj-jq93-j3p7", - "modified": "2023-05-08T15:30:18Z", + "modified": "2023-05-12T18:30:24Z", "published": "2023-05-08T15:30:18Z", "aliases": [ "CVE-2021-27280" ], "details": "OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-xgf4-6mjg-7hqq/GHSA-xgf4-6mjg-7hqq.json b/advisories/unreviewed/2023/05/GHSA-xgf4-6mjg-7hqq/GHSA-xgf4-6mjg-7hqq.json index 40a14eab498..ebf0da46344 100644 --- a/advisories/unreviewed/2023/05/GHSA-xgf4-6mjg-7hqq/GHSA-xgf4-6mjg-7hqq.json +++ b/advisories/unreviewed/2023/05/GHSA-xgf4-6mjg-7hqq/GHSA-xgf4-6mjg-7hqq.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-617" ], "severity": null, "github_reviewed": false,