From d0f354b5763f8efc782fbb76482dae466c186882 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 4 May 2023 03:31:36 +0000 Subject: [PATCH] Publish Advisories GHSA-2fm4-723x-jv9m GHSA-cwgx-5xgj-8rrp GHSA-m69h-4frq-vwq7 GHSA-mf3g-qwcj-jpvf GHSA-mphm-gqh9-q59x GHSA-rhgc-74xq-pwjh GHSA-xjmx-fv6v-2m3q --- .../GHSA-2fm4-723x-jv9m.json | 39 +++++++++++++++++ .../GHSA-cwgx-5xgj-8rrp.json | 39 +++++++++++++++++ .../GHSA-m69h-4frq-vwq7.json | 39 +++++++++++++++++ .../GHSA-mf3g-qwcj-jpvf.json | 39 +++++++++++++++++ .../GHSA-mphm-gqh9-q59x.json | 39 +++++++++++++++++ .../GHSA-rhgc-74xq-pwjh.json | 39 +++++++++++++++++ .../GHSA-xjmx-fv6v-2m3q.json | 43 +++++++++++++++++++ 7 files changed, 277 insertions(+) create mode 100644 advisories/unreviewed/2023/05/GHSA-2fm4-723x-jv9m/GHSA-2fm4-723x-jv9m.json create mode 100644 advisories/unreviewed/2023/05/GHSA-cwgx-5xgj-8rrp/GHSA-cwgx-5xgj-8rrp.json create mode 100644 advisories/unreviewed/2023/05/GHSA-m69h-4frq-vwq7/GHSA-m69h-4frq-vwq7.json create mode 100644 advisories/unreviewed/2023/05/GHSA-mf3g-qwcj-jpvf/GHSA-mf3g-qwcj-jpvf.json create mode 100644 advisories/unreviewed/2023/05/GHSA-mphm-gqh9-q59x/GHSA-mphm-gqh9-q59x.json create mode 100644 advisories/unreviewed/2023/05/GHSA-rhgc-74xq-pwjh/GHSA-rhgc-74xq-pwjh.json create mode 100644 advisories/unreviewed/2023/05/GHSA-xjmx-fv6v-2m3q/GHSA-xjmx-fv6v-2m3q.json diff --git a/advisories/unreviewed/2023/05/GHSA-2fm4-723x-jv9m/GHSA-2fm4-723x-jv9m.json b/advisories/unreviewed/2023/05/GHSA-2fm4-723x-jv9m/GHSA-2fm4-723x-jv9m.json new file mode 100644 index 00000000000..727450443a5 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-2fm4-723x-jv9m/GHSA-2fm4-723x-jv9m.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fm4-723x-jv9m", + "modified": "2023-05-04T03:30:22Z", + "published": "2023-05-04T03:30:22Z", + "aliases": [ + "CVE-2023-31099" + ], + "details": "Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31099" + }, + { + "type": "WEB", + "url": "https://manageengine.com" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/network-monitoring/security-updates/cve-2023-31099.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-cwgx-5xgj-8rrp/GHSA-cwgx-5xgj-8rrp.json b/advisories/unreviewed/2023/05/GHSA-cwgx-5xgj-8rrp/GHSA-cwgx-5xgj-8rrp.json new file mode 100644 index 00000000000..5dbb0e65319 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-cwgx-5xgj-8rrp/GHSA-cwgx-5xgj-8rrp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwgx-5xgj-8rrp", + "modified": "2023-05-04T03:30:22Z", + "published": "2023-05-04T03:30:22Z", + "aliases": [ + "CVE-2023-30077" + ], + "details": "Judging Management System v1.0 by oretnom23 was discovered to vulnerable to SQL injection via /php-jms/review_result.php?mainevent_id=, mainevent_id.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30077" + }, + { + "type": "WEB", + "url": "https://github.com/Dzero57/cve_report/blob/main/judging-management-system/SQLi-1.md" + }, + { + "type": "WEB", + "url": "https://www.github.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-m69h-4frq-vwq7/GHSA-m69h-4frq-vwq7.json b/advisories/unreviewed/2023/05/GHSA-m69h-4frq-vwq7/GHSA-m69h-4frq-vwq7.json new file mode 100644 index 00000000000..d1d8b73012c --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-m69h-4frq-vwq7/GHSA-m69h-4frq-vwq7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m69h-4frq-vwq7", + "modified": "2023-05-04T03:30:22Z", + "published": "2023-05-04T03:30:22Z", + "aliases": [ + "CVE-2023-30331" + ], + "details": "An issue in the render function of beetl v3.15.0 allows attackers to execute server-side template injection (SSTI) via a crafted payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30331" + }, + { + "type": "WEB", + "url": "https://gitee.com/xiandafu/beetl/issues/I6RUIP" + }, + { + "type": "WEB", + "url": "https://github.com/luelueking/Beetl-3.15.0-vuln-poc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-mf3g-qwcj-jpvf/GHSA-mf3g-qwcj-jpvf.json b/advisories/unreviewed/2023/05/GHSA-mf3g-qwcj-jpvf/GHSA-mf3g-qwcj-jpvf.json new file mode 100644 index 00000000000..9ec7b3fc1ef --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-mf3g-qwcj-jpvf/GHSA-mf3g-qwcj-jpvf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf3g-qwcj-jpvf", + "modified": "2023-05-04T03:30:22Z", + "published": "2023-05-04T03:30:22Z", + "aliases": [ + "CVE-2023-25438" + ], + "details": "An issue was discovered in Genomedics MilleGP5 5.9.2, allows remote attackers to execute arbitrary code and gain escalated privileges via modifying specific files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25438" + }, + { + "type": "WEB", + "url": "https://millegpg.it/" + }, + { + "type": "WEB", + "url": "https://packetstormsecurity.com/files/172052/MilleGPG5-5.9.2-Local-Privilege-Escalation.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-mphm-gqh9-q59x/GHSA-mphm-gqh9-q59x.json b/advisories/unreviewed/2023/05/GHSA-mphm-gqh9-q59x/GHSA-mphm-gqh9-q59x.json new file mode 100644 index 00000000000..0052f765ac8 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-mphm-gqh9-q59x/GHSA-mphm-gqh9-q59x.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mphm-gqh9-q59x", + "modified": "2023-05-04T03:30:22Z", + "published": "2023-05-04T03:30:22Z", + "aliases": [ + "CVE-2023-27075" + ], + "details": "A cross-site scripting vulnerability (XSS) in the component microbin/src/pasta.rs of Microbin v1.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27075" + }, + { + "type": "WEB", + "url": "https://github.com/szabodanika/microbin/issues/142" + }, + { + "type": "WEB", + "url": "https://github.com/szabodanika/microbin/pull/143" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-rhgc-74xq-pwjh/GHSA-rhgc-74xq-pwjh.json b/advisories/unreviewed/2023/05/GHSA-rhgc-74xq-pwjh/GHSA-rhgc-74xq-pwjh.json new file mode 100644 index 00000000000..2884fa07c20 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-rhgc-74xq-pwjh/GHSA-rhgc-74xq-pwjh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rhgc-74xq-pwjh", + "modified": "2023-05-04T03:30:22Z", + "published": "2023-05-04T03:30:22Z", + "aliases": [ + "CVE-2023-27568" + ], + "details": "SQL injection vulnerability inSpryker Commerce OS 0.9 that allows for access to sensitive data via customer/order?orderSearchForm[searchText]=", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27568" + }, + { + "type": "WEB", + "url": "https://www.schutzwerk.com/advisories/SCHUTZWERK-SA-2023-001.txt" + }, + { + "type": "WEB", + "url": "https://www.schutzwerk.com/blog/schutzwerk-sa-2023-001/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/05/GHSA-xjmx-fv6v-2m3q/GHSA-xjmx-fv6v-2m3q.json b/advisories/unreviewed/2023/05/GHSA-xjmx-fv6v-2m3q/GHSA-xjmx-fv6v-2m3q.json new file mode 100644 index 00000000000..6f105aab5e0 --- /dev/null +++ b/advisories/unreviewed/2023/05/GHSA-xjmx-fv6v-2m3q/GHSA-xjmx-fv6v-2m3q.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjmx-fv6v-2m3q", + "modified": "2023-05-04T03:30:22Z", + "published": "2023-05-04T03:30:22Z", + "aliases": [ + "CVE-2023-29842" + ], + "details": "ChirchCRm 4.5.4 endpoint /EditEventTypes.php is vulnerable to Blind SQL Injection (Time-based) via the EN_tyid POST parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29842" + }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM" + }, + { + "type": "WEB", + "url": "https://github.com/arvandy/CVE/blob/main/CVE-2023-29842/CVE-2023-29842.md" + }, + { + "type": "WEB", + "url": "https://github.com/arvandy/CVE/blob/main/CVE-2023-29842/CVE-2023-29842.py" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file