Publish Advisories

GHSA-2fm4-723x-jv9m
GHSA-cwgx-5xgj-8rrp
GHSA-m69h-4frq-vwq7
GHSA-mf3g-qwcj-jpvf
GHSA-mphm-gqh9-q59x
GHSA-rhgc-74xq-pwjh
GHSA-xjmx-fv6v-2m3q
This commit is contained in:
advisory-database[bot]
2023-05-04 03:31:36 +00:00
parent d6749b64fd
commit d0f354b576
7 changed files with 277 additions and 0 deletions
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2fm4-723x-jv9m",
"modified": "2023-05-04T03:30:22Z",
"published": "2023-05-04T03:30:22Z",
"aliases": [
"CVE-2023-31099"
],
"details": "Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31099"
},
{
"type": "WEB",
"url": "https://manageengine.com"
},
{
"type": "WEB",
"url": "https://www.manageengine.com/network-monitoring/security-updates/cve-2023-31099.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cwgx-5xgj-8rrp",
"modified": "2023-05-04T03:30:22Z",
"published": "2023-05-04T03:30:22Z",
"aliases": [
"CVE-2023-30077"
],
"details": "Judging Management System v1.0 by oretnom23 was discovered to vulnerable to SQL injection via /php-jms/review_result.php?mainevent_id=, mainevent_id.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30077"
},
{
"type": "WEB",
"url": "https://github.com/Dzero57/cve_report/blob/main/judging-management-system/SQLi-1.md"
},
{
"type": "WEB",
"url": "https://www.github.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m69h-4frq-vwq7",
"modified": "2023-05-04T03:30:22Z",
"published": "2023-05-04T03:30:22Z",
"aliases": [
"CVE-2023-30331"
],
"details": "An issue in the render function of beetl v3.15.0 allows attackers to execute server-side template injection (SSTI) via a crafted payload.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30331"
},
{
"type": "WEB",
"url": "https://gitee.com/xiandafu/beetl/issues/I6RUIP"
},
{
"type": "WEB",
"url": "https://github.com/luelueking/Beetl-3.15.0-vuln-poc"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mf3g-qwcj-jpvf",
"modified": "2023-05-04T03:30:22Z",
"published": "2023-05-04T03:30:22Z",
"aliases": [
"CVE-2023-25438"
],
"details": "An issue was discovered in Genomedics MilleGP5 5.9.2, allows remote attackers to execute arbitrary code and gain escalated privileges via modifying specific files.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25438"
},
{
"type": "WEB",
"url": "https://millegpg.it/"
},
{
"type": "WEB",
"url": "https://packetstormsecurity.com/files/172052/MilleGPG5-5.9.2-Local-Privilege-Escalation.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mphm-gqh9-q59x",
"modified": "2023-05-04T03:30:22Z",
"published": "2023-05-04T03:30:22Z",
"aliases": [
"CVE-2023-27075"
],
"details": "A cross-site scripting vulnerability (XSS) in the component microbin/src/pasta.rs of Microbin v1.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27075"
},
{
"type": "WEB",
"url": "https://github.com/szabodanika/microbin/issues/142"
},
{
"type": "WEB",
"url": "https://github.com/szabodanika/microbin/pull/143"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rhgc-74xq-pwjh",
"modified": "2023-05-04T03:30:22Z",
"published": "2023-05-04T03:30:22Z",
"aliases": [
"CVE-2023-27568"
],
"details": "SQL injection vulnerability inSpryker Commerce OS 0.9 that allows for access to sensitive data via customer/order?orderSearchForm[searchText]=",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27568"
},
{
"type": "WEB",
"url": "https://www.schutzwerk.com/advisories/SCHUTZWERK-SA-2023-001.txt"
},
{
"type": "WEB",
"url": "https://www.schutzwerk.com/blog/schutzwerk-sa-2023-001/"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xjmx-fv6v-2m3q",
"modified": "2023-05-04T03:30:22Z",
"published": "2023-05-04T03:30:22Z",
"aliases": [
"CVE-2023-29842"
],
"details": "ChirchCRm 4.5.4 endpoint /EditEventTypes.php is vulnerable to Blind SQL Injection (Time-based) via the EN_tyid POST parameter.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29842"
},
{
"type": "WEB",
"url": "https://github.com/ChurchCRM/CRM"
},
{
"type": "WEB",
"url": "https://github.com/arvandy/CVE/blob/main/CVE-2023-29842/CVE-2023-29842.md"
},
{
"type": "WEB",
"url": "https://github.com/arvandy/CVE/blob/main/CVE-2023-29842/CVE-2023-29842.py"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}