diff --git a/advisories/unreviewed/2024/10/GHSA-5w4r-4gwh-5f24/GHSA-5w4r-4gwh-5f24.json b/advisories/unreviewed/2024/10/GHSA-5w4r-4gwh-5f24/GHSA-5w4r-4gwh-5f24.json new file mode 100644 index 00000000000..36ece0014bf --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5w4r-4gwh-5f24/GHSA-5w4r-4gwh-5f24.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w4r-4gwh-5f24", + "modified": "2024-10-21T03:30:29Z", + "published": "2024-10-21T03:30:29Z", + "aliases": [ + "CVE-2024-49215" + ], + "details": "An issue was discovered in Sangoma Asterisk through 18.20.0, 19.x and 20.x through 20.5.0, and 21.x through 21.0.0, and Certified Asterisk through 18.9-cert5. In manager.c, the functions action_getconfig() and action_getconfigJson() do not process the input file path, resulting in a path traversal vulnerability. In versions without the restrictedFile() function, no processing is done on the input path. In versions with the restrictedFile() function, path traversal is not processed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49215" + }, + { + "type": "WEB", + "url": "https://gist.github.com/hyp164D1/5d68b9b7a504f1416272a825ce65966a" + }, + { + "type": "WEB", + "url": "https://github.com/asterisk/asterisk/blob/20.5.0/main/manager.c#L3755" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T01:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-63vh-qfjc-gpw5/GHSA-63vh-qfjc-gpw5.json b/advisories/unreviewed/2024/10/GHSA-63vh-qfjc-gpw5/GHSA-63vh-qfjc-gpw5.json new file mode 100644 index 00000000000..4e76264cb16 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-63vh-qfjc-gpw5/GHSA-63vh-qfjc-gpw5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63vh-qfjc-gpw5", + "modified": "2024-10-21T03:30:29Z", + "published": "2024-10-21T03:30:29Z", + "aliases": [ + "CVE-2024-43689" + ], + "details": "Stack-based buffer overflow vulnerability exists in WAB-I1750-PS and WAB-S1167-PS. By processing a specially crafted HTTP request, arbitrary code may be executed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43689" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN24885537" + }, + { + "type": "WEB", + "url": "https://www.elecom.co.jp/news/security/20240827-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T02:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9g3x-jc4v-gjcv/GHSA-9g3x-jc4v-gjcv.json b/advisories/unreviewed/2024/10/GHSA-9g3x-jc4v-gjcv/GHSA-9g3x-jc4v-gjcv.json new file mode 100644 index 00000000000..e0c8cbbe939 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9g3x-jc4v-gjcv/GHSA-9g3x-jc4v-gjcv.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9g3x-jc4v-gjcv", + "modified": "2024-10-21T03:30:29Z", + "published": "2024-10-21T03:30:29Z", + "aliases": [ + "CVE-2024-10197" + ], + "details": "A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /manage_supplier.php of the component Manage Supplier Page. The manipulation of the argument address leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10197" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://gist.github.com/higordiego/bc051be4a8c6b6641578cad533742aab" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.281022" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.281022" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.426884" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T01:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gvw2-v8vf-2fmw/GHSA-gvw2-v8vf-2fmw.json b/advisories/unreviewed/2024/10/GHSA-gvw2-v8vf-2fmw/GHSA-gvw2-v8vf-2fmw.json new file mode 100644 index 00000000000..63a05649d0f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-gvw2-v8vf-2fmw/GHSA-gvw2-v8vf-2fmw.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvw2-v8vf-2fmw", + "modified": "2024-10-21T03:30:29Z", + "published": "2024-10-21T03:30:29Z", + "aliases": [ + "CVE-2024-10196" + ], + "details": "A vulnerability was found in code-projects Pharmacy Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /add_new_invoice.php. The manipulation of the argument text leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10196" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://gist.github.com/higordiego/be616d2853a9f1820d8558fc00e97e24" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.281021" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.281021" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.426862" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T01:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vq2f-wpjw-qjm7/GHSA-vq2f-wpjw-qjm7.json b/advisories/unreviewed/2024/10/GHSA-vq2f-wpjw-qjm7/GHSA-vq2f-wpjw-qjm7.json new file mode 100644 index 00000000000..130a0b7c1ef --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vq2f-wpjw-qjm7/GHSA-vq2f-wpjw-qjm7.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq2f-wpjw-qjm7", + "modified": "2024-10-21T03:30:29Z", + "published": "2024-10-21T03:30:29Z", + "aliases": [ + "CVE-2024-10198" + ], + "details": "A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /manage_customer.php of the component Manage Customer Page. The manipulation of the argument suppliers_name/address leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions contradicting files to be affected. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10198" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://gist.github.com/higordiego/93343006341d3799de0cb8912cc328ec" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.281023" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.281023" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.426885" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T02:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wv3w-5m8g-gghx/GHSA-wv3w-5m8g-gghx.json b/advisories/unreviewed/2024/10/GHSA-wv3w-5m8g-gghx/GHSA-wv3w-5m8g-gghx.json new file mode 100644 index 00000000000..9037ecbd52b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wv3w-5m8g-gghx/GHSA-wv3w-5m8g-gghx.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wv3w-5m8g-gghx", + "modified": "2024-10-21T03:30:29Z", + "published": "2024-10-21T03:30:29Z", + "aliases": [ + "CVE-2024-10199" + ], + "details": "A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /manage_medicine.php of the component Manage Medicines Page. The manipulation of the argument name/address/doctor_address/suppliers_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions contradicting files to be affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10199" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://gist.github.com/higordiego/0dae6dd4a36acd12bcc408caf1c787d9" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.281024" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.281024" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.426916" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T02:15:02Z" + } +} \ No newline at end of file