Publish Advisories

GHSA-5w4r-4gwh-5f24
GHSA-63vh-qfjc-gpw5
GHSA-9g3x-jc4v-gjcv
GHSA-gvw2-v8vf-2fmw
GHSA-vq2f-wpjw-qjm7
GHSA-wv3w-5m8g-gghx
This commit is contained in:
advisory-database[bot]
2024-10-21 03:31:55 +00:00
parent 9becac37b0
commit ce3b269d08
6 changed files with 310 additions and 0 deletions
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5w4r-4gwh-5f24",
"modified": "2024-10-21T03:30:29Z",
"published": "2024-10-21T03:30:29Z",
"aliases": [
"CVE-2024-49215"
],
"details": "An issue was discovered in Sangoma Asterisk through 18.20.0, 19.x and 20.x through 20.5.0, and 21.x through 21.0.0, and Certified Asterisk through 18.9-cert5. In manager.c, the functions action_getconfig() and action_getconfigJson() do not process the input file path, resulting in a path traversal vulnerability. In versions without the restrictedFile() function, no processing is done on the input path. In versions with the restrictedFile() function, path traversal is not processed.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49215"
},
{
"type": "WEB",
"url": "https://gist.github.com/hyp164D1/5d68b9b7a504f1416272a825ce65966a"
},
{
"type": "WEB",
"url": "https://github.com/asterisk/asterisk/blob/20.5.0/main/manager.c#L3755"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-21T01:15:02Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-63vh-qfjc-gpw5",
"modified": "2024-10-21T03:30:29Z",
"published": "2024-10-21T03:30:29Z",
"aliases": [
"CVE-2024-43689"
],
"details": "Stack-based buffer overflow vulnerability exists in WAB-I1750-PS and WAB-S1167-PS. By processing a specially crafted HTTP request, arbitrary code may be executed.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43689"
},
{
"type": "WEB",
"url": "https://jvn.jp/en/jp/JVN24885537"
},
{
"type": "WEB",
"url": "https://www.elecom.co.jp/news/security/20240827-01"
}
],
"database_specific": {
"cwe_ids": [
"CWE-121"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-21T02:15:02Z"
}
}
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9g3x-jc4v-gjcv",
"modified": "2024-10-21T03:30:29Z",
"published": "2024-10-21T03:30:29Z",
"aliases": [
"CVE-2024-10197"
],
"details": "A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /manage_supplier.php of the component Manage Supplier Page. The manipulation of the argument address leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10197"
},
{
"type": "WEB",
"url": "https://code-projects.org"
},
{
"type": "WEB",
"url": "https://gist.github.com/higordiego/bc051be4a8c6b6641578cad533742aab"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.281022"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.281022"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.426884"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-21T01:15:02Z"
}
}
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gvw2-v8vf-2fmw",
"modified": "2024-10-21T03:30:29Z",
"published": "2024-10-21T03:30:29Z",
"aliases": [
"CVE-2024-10196"
],
"details": "A vulnerability was found in code-projects Pharmacy Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /add_new_invoice.php. The manipulation of the argument text leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10196"
},
{
"type": "WEB",
"url": "https://code-projects.org"
},
{
"type": "WEB",
"url": "https://gist.github.com/higordiego/be616d2853a9f1820d8558fc00e97e24"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.281021"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.281021"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.426862"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-21T01:15:02Z"
}
}
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vq2f-wpjw-qjm7",
"modified": "2024-10-21T03:30:29Z",
"published": "2024-10-21T03:30:29Z",
"aliases": [
"CVE-2024-10198"
],
"details": "A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /manage_customer.php of the component Manage Customer Page. The manipulation of the argument suppliers_name/address leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions contradicting files to be affected. Other parameters might be affected as well.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10198"
},
{
"type": "WEB",
"url": "https://code-projects.org"
},
{
"type": "WEB",
"url": "https://gist.github.com/higordiego/93343006341d3799de0cb8912cc328ec"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.281023"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.281023"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.426885"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-21T02:15:02Z"
}
}
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wv3w-5m8g-gghx",
"modified": "2024-10-21T03:30:29Z",
"published": "2024-10-21T03:30:29Z",
"aliases": [
"CVE-2024-10199"
],
"details": "A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /manage_medicine.php of the component Manage Medicines Page. The manipulation of the argument name/address/doctor_address/suppliers_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions contradicting files to be affected.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10199"
},
{
"type": "WEB",
"url": "https://code-projects.org"
},
{
"type": "WEB",
"url": "https://gist.github.com/higordiego/0dae6dd4a36acd12bcc408caf1c787d9"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.281024"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.281024"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.426916"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-21T02:15:02Z"
}
}