From cfc7e0907605e33179fd11879cce529fb24b403e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 21 Mar 2024 18:33:39 +0000 Subject: [PATCH] Publish Advisories GHSA-3qv4-jm22-wqx7 GHSA-5rwj-59p7-5wj5 GHSA-9397-pxm9-3w6r GHSA-9pxg-gf82-j5w9 GHSA-cg72-65f8-rpjf GHSA-px62-j2m3-mvc3 GHSA-q2gq-mg46-qq2m GHSA-qfvj-334p-gg47 GHSA-qw3x-hp2h-3hcq GHSA-r8h7-q43f-c88r GHSA-v7mx-cxcx-v2fh GHSA-w7x3-wfj7-w6gw GHSA-xph7-pm58-q56v GHSA-xv4r-44qp-78wm --- .../GHSA-3qv4-jm22-wqx7.json | 43 +++++++++++++++++++ .../GHSA-5rwj-59p7-5wj5.json | 38 ++++++++++++++++ .../GHSA-9397-pxm9-3w6r.json | 38 ++++++++++++++++ .../GHSA-9pxg-gf82-j5w9.json | 38 ++++++++++++++++ .../GHSA-cg72-65f8-rpjf.json | 38 ++++++++++++++++ .../GHSA-px62-j2m3-mvc3.json | 38 ++++++++++++++++ .../GHSA-q2gq-mg46-qq2m.json | 38 ++++++++++++++++ .../GHSA-qfvj-334p-gg47.json | 38 ++++++++++++++++ .../GHSA-qw3x-hp2h-3hcq.json | 35 +++++++++++++++ .../GHSA-r8h7-q43f-c88r.json | 38 ++++++++++++++++ .../GHSA-v7mx-cxcx-v2fh.json | 38 ++++++++++++++++ .../GHSA-w7x3-wfj7-w6gw.json | 42 ++++++++++++++++++ .../GHSA-xph7-pm58-q56v.json | 38 ++++++++++++++++ .../GHSA-xv4r-44qp-78wm.json | 38 ++++++++++++++++ 14 files changed, 538 insertions(+) create mode 100644 advisories/unreviewed/2024/03/GHSA-3qv4-jm22-wqx7/GHSA-3qv4-jm22-wqx7.json create mode 100644 advisories/unreviewed/2024/03/GHSA-5rwj-59p7-5wj5/GHSA-5rwj-59p7-5wj5.json create mode 100644 advisories/unreviewed/2024/03/GHSA-9397-pxm9-3w6r/GHSA-9397-pxm9-3w6r.json create mode 100644 advisories/unreviewed/2024/03/GHSA-9pxg-gf82-j5w9/GHSA-9pxg-gf82-j5w9.json create mode 100644 advisories/unreviewed/2024/03/GHSA-cg72-65f8-rpjf/GHSA-cg72-65f8-rpjf.json create mode 100644 advisories/unreviewed/2024/03/GHSA-px62-j2m3-mvc3/GHSA-px62-j2m3-mvc3.json create mode 100644 advisories/unreviewed/2024/03/GHSA-q2gq-mg46-qq2m/GHSA-q2gq-mg46-qq2m.json create mode 100644 advisories/unreviewed/2024/03/GHSA-qfvj-334p-gg47/GHSA-qfvj-334p-gg47.json create mode 100644 advisories/unreviewed/2024/03/GHSA-qw3x-hp2h-3hcq/GHSA-qw3x-hp2h-3hcq.json create mode 100644 advisories/unreviewed/2024/03/GHSA-r8h7-q43f-c88r/GHSA-r8h7-q43f-c88r.json create mode 100644 advisories/unreviewed/2024/03/GHSA-v7mx-cxcx-v2fh/GHSA-v7mx-cxcx-v2fh.json create mode 100644 advisories/unreviewed/2024/03/GHSA-w7x3-wfj7-w6gw/GHSA-w7x3-wfj7-w6gw.json create mode 100644 advisories/unreviewed/2024/03/GHSA-xph7-pm58-q56v/GHSA-xph7-pm58-q56v.json create mode 100644 advisories/unreviewed/2024/03/GHSA-xv4r-44qp-78wm/GHSA-xv4r-44qp-78wm.json diff --git a/advisories/unreviewed/2024/03/GHSA-3qv4-jm22-wqx7/GHSA-3qv4-jm22-wqx7.json b/advisories/unreviewed/2024/03/GHSA-3qv4-jm22-wqx7/GHSA-3qv4-jm22-wqx7.json new file mode 100644 index 00000000000..999b4e5e849 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-3qv4-jm22-wqx7/GHSA-3qv4-jm22-wqx7.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qv4-jm22-wqx7", + "modified": "2024-03-21T18:32:03Z", + "published": "2024-03-21T18:32:03Z", + "aliases": [ + "CVE-2024-29916" + ], + "details": "The dormakaba Saflok system before the November 2023 software update allows an attacker to unlock arbitrary doors at a property via forged keycards, if the attacker has obtained one active or expired keycard for the specific property, aka the \"Unsaflok\" issue. This occurs, in part, because the key derivation function relies only on a UID. This affects, for example, Saflok MT, and the Confidant, Quantum, RT, and Saffire series.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29916" + }, + { + "type": "WEB", + "url": "https://news.ycombinator.com/item?id=39779291" + }, + { + "type": "WEB", + "url": "https://unsaflok.com" + }, + { + "type": "WEB", + "url": "https://www.wired.com/story/saflok-hotel-lock-unsaflok-hack-technique" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5rwj-59p7-5wj5/GHSA-5rwj-59p7-5wj5.json b/advisories/unreviewed/2024/03/GHSA-5rwj-59p7-5wj5/GHSA-5rwj-59p7-5wj5.json new file mode 100644 index 00000000000..947000bff5d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-5rwj-59p7-5wj5/GHSA-5rwj-59p7-5wj5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rwj-59p7-5wj5", + "modified": "2024-03-21T18:32:03Z", + "published": "2024-03-21T18:32:03Z", + "aliases": [ + "CVE-2024-27968" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Optimole Super Page Cache for Cloudflare allows Stored XSS.This issue affects Super Page Cache for Cloudflare: from n/a through 4.7.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27968" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-cloudflare-page-cache/wordpress-super-page-cache-for-cloudflare-plugin-4-7-5-cross-site-request-forgery-csrf-to-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9397-pxm9-3w6r/GHSA-9397-pxm9-3w6r.json b/advisories/unreviewed/2024/03/GHSA-9397-pxm9-3w6r/GHSA-9397-pxm9-3w6r.json new file mode 100644 index 00000000000..c3ad3e59784 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9397-pxm9-3w6r/GHSA-9397-pxm9-3w6r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9397-pxm9-3w6r", + "modified": "2024-03-21T18:32:03Z", + "published": "2024-03-21T18:32:03Z", + "aliases": [ + "CVE-2024-27965" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels Team WPFunnels allows Stored XSS.This issue affects WPFunnels: from n/a through 3.0.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27965" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpfunnels/wordpress-wpfunnels-plugin-3-0-6-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-9pxg-gf82-j5w9/GHSA-9pxg-gf82-j5w9.json b/advisories/unreviewed/2024/03/GHSA-9pxg-gf82-j5w9/GHSA-9pxg-gf82-j5w9.json new file mode 100644 index 00000000000..b331d47b86d --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-9pxg-gf82-j5w9/GHSA-9pxg-gf82-j5w9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pxg-gf82-j5w9", + "modified": "2024-03-21T18:32:03Z", + "published": "2024-03-21T18:32:03Z", + "aliases": [ + "CVE-2024-27962" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Florian 'fkrauthan' Krauthan allows Reflected XSS.This issue affects wp-mpdf: from n/a through 3.7.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27962" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-mpdf/wordpress-wp-mpdf-plugin-3-7-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-cg72-65f8-rpjf/GHSA-cg72-65f8-rpjf.json b/advisories/unreviewed/2024/03/GHSA-cg72-65f8-rpjf/GHSA-cg72-65f8-rpjf.json new file mode 100644 index 00000000000..49af32a7cc2 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-cg72-65f8-rpjf/GHSA-cg72-65f8-rpjf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg72-65f8-rpjf", + "modified": "2024-03-21T18:32:02Z", + "published": "2024-03-21T18:32:02Z", + "aliases": [ + "CVE-2022-44595" + ], + "details": "Improper Authentication vulnerability in Melapress WP 2FA allows Authentication Bypass.This issue affects WP 2FA: from n/a through 2.2.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44595" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-2fa/wordpress-wp2fa-plugin-2-2-0-broken-authentication-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-px62-j2m3-mvc3/GHSA-px62-j2m3-mvc3.json b/advisories/unreviewed/2024/03/GHSA-px62-j2m3-mvc3/GHSA-px62-j2m3-mvc3.json new file mode 100644 index 00000000000..8e7a0c48ae3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-px62-j2m3-mvc3/GHSA-px62-j2m3-mvc3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px62-j2m3-mvc3", + "modified": "2024-03-21T18:32:03Z", + "published": "2024-03-21T18:32:03Z", + "aliases": [ + "CVE-2024-2580" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Automation By Autonami allows Stored XSS.This issue affects Automation By Autonami: from n/a through 2.8.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2580" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-marketing-automations/wordpress-recover-woocommerce-cart-abandonment-newsletter-email-marketing-marketing-automation-by-funnelkit-plugin-2-8-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-q2gq-mg46-qq2m/GHSA-q2gq-mg46-qq2m.json b/advisories/unreviewed/2024/03/GHSA-q2gq-mg46-qq2m/GHSA-q2gq-mg46-qq2m.json new file mode 100644 index 00000000000..3b2e7e113c3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-q2gq-mg46-qq2m/GHSA-q2gq-mg46-qq2m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2gq-mg46-qq2m", + "modified": "2024-03-21T18:32:03Z", + "published": "2024-03-21T18:32:03Z", + "aliases": [ + "CVE-2024-2579" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Tracking Code Manager.This issue affects Tracking Code Manager: from n/a through 2.0.16.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2579" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/tracking-code-manager/wordpress-tracking-code-manager-plugin-2-0-16-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qfvj-334p-gg47/GHSA-qfvj-334p-gg47.json b/advisories/unreviewed/2024/03/GHSA-qfvj-334p-gg47/GHSA-qfvj-334p-gg47.json new file mode 100644 index 00000000000..5519fc3b3c1 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qfvj-334p-gg47/GHSA-qfvj-334p-gg47.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfvj-334p-gg47", + "modified": "2024-03-21T18:32:03Z", + "published": "2024-03-21T18:32:03Z", + "aliases": [ + "CVE-2024-27190" + ], + "details": "Missing Authorization vulnerability in Jean-David Daviet Download Media.This issue affects Download Media: from n/a through 1.4.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27190" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/download-media/wordpress-download-media-plugin-1-4-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-qw3x-hp2h-3hcq/GHSA-qw3x-hp2h-3hcq.json b/advisories/unreviewed/2024/03/GHSA-qw3x-hp2h-3hcq/GHSA-qw3x-hp2h-3hcq.json new file mode 100644 index 00000000000..0f3f8a96227 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-qw3x-hp2h-3hcq/GHSA-qw3x-hp2h-3hcq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw3x-hp2h-3hcq", + "modified": "2024-03-21T18:32:03Z", + "published": "2024-03-21T18:32:03Z", + "aliases": [ + "CVE-2023-49837" + ], + "details": "Uncontrolled Resource Consumption vulnerability in David Artiss Code Embed.This issue affects Code Embed: from n/a through 2.3.6.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49837" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/simple-embed-code/wordpress-embed-code-plugin-2-3-6-denial-of-service-attack-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-r8h7-q43f-c88r/GHSA-r8h7-q43f-c88r.json b/advisories/unreviewed/2024/03/GHSA-r8h7-q43f-c88r/GHSA-r8h7-q43f-c88r.json new file mode 100644 index 00000000000..b4dc1d1e2cf --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-r8h7-q43f-c88r/GHSA-r8h7-q43f-c88r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8h7-q43f-c88r", + "modified": "2024-03-21T18:32:03Z", + "published": "2024-03-21T18:32:03Z", + "aliases": [ + "CVE-2024-27963" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crisp allows Stored XSS.This issue affects Crisp: from n/a through 0.44.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27963" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/crisp/wordpress-crisp-live-chat-and-chatbot-plugin-0-44-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-v7mx-cxcx-v2fh/GHSA-v7mx-cxcx-v2fh.json b/advisories/unreviewed/2024/03/GHSA-v7mx-cxcx-v2fh/GHSA-v7mx-cxcx-v2fh.json new file mode 100644 index 00000000000..28b7215b35b --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-v7mx-cxcx-v2fh/GHSA-v7mx-cxcx-v2fh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7mx-cxcx-v2fh", + "modified": "2024-03-21T18:32:03Z", + "published": "2024-03-21T18:32:03Z", + "aliases": [ + "CVE-2024-27964" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.9.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27964" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/zippy/wordpress-zippy-plugin-1-6-9-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-w7x3-wfj7-w6gw/GHSA-w7x3-wfj7-w6gw.json b/advisories/unreviewed/2024/03/GHSA-w7x3-wfj7-w6gw/GHSA-w7x3-wfj7-w6gw.json new file mode 100644 index 00000000000..2f0363daaf3 --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-w7x3-wfj7-w6gw/GHSA-w7x3-wfj7-w6gw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7x3-wfj7-w6gw", + "modified": "2024-03-21T18:32:03Z", + "published": "2024-03-21T18:32:03Z", + "aliases": [ + "CVE-2024-27277" + ], + "details": "The private key for the IBM Storage Protect Plus Server 10.1.0 through 10.1.16 certificate can be disclosed, undermining the security of the certificate. IBM X-Force ID: 285205.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27277" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/285205" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7144861" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-xph7-pm58-q56v/GHSA-xph7-pm58-q56v.json b/advisories/unreviewed/2024/03/GHSA-xph7-pm58-q56v/GHSA-xph7-pm58-q56v.json new file mode 100644 index 00000000000..bc06ccd1caa --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-xph7-pm58-q56v/GHSA-xph7-pm58-q56v.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xph7-pm58-q56v", + "modified": "2024-03-21T18:32:03Z", + "published": "2024-03-21T18:32:03Z", + "aliases": [ + "CVE-2024-2578" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPCoder WP Coder allows Stored XSS.This issue affects WP Coder: from n/a through 3.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2578" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-coder/wordpress-wp-coder-plugin-3-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T17:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-xv4r-44qp-78wm/GHSA-xv4r-44qp-78wm.json b/advisories/unreviewed/2024/03/GHSA-xv4r-44qp-78wm/GHSA-xv4r-44qp-78wm.json new file mode 100644 index 00000000000..391791af8ce --- /dev/null +++ b/advisories/unreviewed/2024/03/GHSA-xv4r-44qp-78wm/GHSA-xv4r-44qp-78wm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv4r-44qp-78wm", + "modified": "2024-03-21T18:32:03Z", + "published": "2024-03-21T18:32:03Z", + "aliases": [ + "CVE-2024-27956" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27956" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-automatic/wordpress-automatic-plugin-3-92-0-unauthenticated-arbitrary-sql-execution-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-03-21T17:15:08Z" + } +} \ No newline at end of file