Publish Advisories

GHSA-32qx-x64f-2vp2
GHSA-59xg-j66j-wgvc
GHSA-657j-69g5-mr77
GHSA-6f85-3hg7-g6mc
GHSA-6m2g-9wxv-m6w5
GHSA-72pg-72hh-vvpx
GHSA-7ccp-f4gp-c4vq
GHSA-cmj5-7h2c-856r
GHSA-f7vw-6h99-wmxg
GHSA-fhrg-g7p2-r2f3
GHSA-g37v-c843-6cw3
GHSA-h8c6-6ff8-4h69
GHSA-hmvr-jmxq-q9hj
GHSA-hv56-x76m-qpj5
GHSA-jhvx-96xq-qggm
GHSA-jj5x-5vg3-9m7f
GHSA-m99q-89rr-5mvx
GHSA-p45m-mr9q-rx4p
GHSA-pvgx-v84j-v63h
GHSA-q6fh-vc2v-h383
GHSA-q96x-mjr8-2jrj
GHSA-rq46-9225-gj4f
This commit is contained in:
advisory-database[bot]
2024-05-23 06:32:14 +00:00
parent 233ee8a9c7
commit d324c37af5
22 changed files with 995 additions and 0 deletions
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-32qx-x64f-2vp2",
"modified": "2024-05-23T06:30:46Z",
"published": "2024-05-23T06:30:46Z",
"aliases": [
"CVE-2024-5177"
],
"details": "The Hash Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' parameter within multiple widgets in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5177"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/hash-elements/trunk/modules/news-module-one/widgets/news-module-one.php#L720"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3090981%40hash-elements%2Ftrunk&old=3089165%40hash-elements%2Ftrunk&sfp_email=&sfph_mail=#file18"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/9ba07137-f834-4f56-bcd5-0f6fde756681?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T06:15:11Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-59xg-j66j-wgvc",
"modified": "2024-05-23T06:30:46Z",
"published": "2024-05-23T06:30:46Z",
"aliases": [
"CVE-2024-5237"
],
"details": "A vulnerability, which was classified as critical, has been found in Campcodes Complete Web-Based School Management System 1.0. Affected by this issue is some unknown functionality of the file /view/timetable_grade_wise.php. The manipulation of the argument grade leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-265988.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5237"
},
{
"type": "WEB",
"url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2027.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.265988"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.265988"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.339813"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T06:15:11Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-657j-69g5-mr77",
"modified": "2024-05-23T06:30:45Z",
"published": "2024-05-23T06:30:45Z",
"aliases": [
"CVE-2024-5235"
],
"details": "A vulnerability classified as critical has been found in Campcodes Complete Web-Based School Management System 1.0. Affected is an unknown function of the file /view/teacher_salary_invoice.php. The manipulation of the argument teacher_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-265986 is the identifier assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5235"
},
{
"type": "WEB",
"url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2025.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.265986"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.265986"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.339811"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T05:15:49Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6f85-3hg7-g6mc",
"modified": "2024-05-23T06:30:45Z",
"published": "2024-05-23T06:30:45Z",
"aliases": [
"CVE-2023-6325"
],
"details": "The RomethemeForm For Elementor plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the export_entries, rtformnewform, and rtformupdate functions in all versions up to, and including, 1.1.5. This makes it possible for unauthenticated attackers to export arbitrary form submissions, create new forms, or update any post title or certain metadata.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6325"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/romethemeform/tags/1.1.2/modules/form/form.php"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3090708/romethemeform/trunk?contextall=1&old=3079080&old_path=%2Fromethemeform%2Ftrunk"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/81a293ea-abda-4c90-a109-791ca5ba89a4?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T05:15:48Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6m2g-9wxv-m6w5",
"modified": "2024-05-23T06:30:46Z",
"published": "2024-05-23T06:30:46Z",
"aliases": [
"CVE-2024-4347"
],
"details": "The WP Fastest Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.6 via the specificDeleteCache function. This makes it possible for authenticated attackers to delete arbitrary files on the server, which can include wp-config.php files of the affected site or other sites in a shared hosting environment.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4347"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/wp-fastest-cache/trunk/wpFastestCache.php#L1342"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3089597%40wp-fastest-cache%2Ftrunk&old=3081797%40wp-fastest-cache%2Ftrunk&sfp_email=&sfph_mail=#file1"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/634d4062-7004-4e89-89a8-323c939aae93?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T06:15:11Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-72pg-72hh-vvpx",
"modified": "2024-05-23T06:30:45Z",
"published": "2024-05-23T06:30:45Z",
"aliases": [
"CVE-2024-3711"
],
"details": "The Brizy Page Builder plugin for WordPress is vulnerable to unauthorized plugin setting update due to a missing capability check on the functions action_request_disable, action_change_template, and action_request_enable in all versions up to, and including, 2.4.43. This makes it possible for authenticated attackers, with contributor access or above, to enable/disable the Brizy editor and modify the template used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3711"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/brizy/trunk/admin/main.php"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3086506%40brizy%2Ftrunk&old=3058896%40brizy%2Ftrunk&sfp_email=&sfph_mail="
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7092ce4a-bad9-4426-b94e-d9d688344272?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T06:15:10Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7ccp-f4gp-c4vq",
"modified": "2024-05-23T06:30:46Z",
"published": "2024-05-23T06:30:46Z",
"aliases": [
"CVE-2024-5239"
],
"details": "A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /view/timetable_update_form.php. The manipulation of the argument grade leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-265990 is the identifier assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5239"
},
{
"type": "WEB",
"url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2029.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.265990"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.265990"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.339815"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T06:15:13Z"
}
}
@@ -0,0 +1,74 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cmj5-7h2c-856r",
"modified": "2024-05-23T06:30:45Z",
"published": "2024-05-23T06:30:45Z",
"aliases": [
"CVE-2024-4431"
],
"details": "The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id parameter in all versions up to, and including, 1.3.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4431"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/lastudio-element-kit/trunk/templates/advanced-carousel/global/simple/items-loop-end.php#L7"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/lastudio-element-kit/trunk/templates/banner-list/global/index.php#L75"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/lastudio-element-kit/trunk/templates/images-layout/global/index.php#L75"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/lastudio-element-kit/trunk/templates/instagram-feed/global/index.php#L75"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/lastudio-element-kit/trunk/templates/posts/global/index.php#L116"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/lastudio-element-kit/trunk/templates/team-member/global/custom.php#L157"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/lastudio-element-kit/trunk/templates/testimonials/global/index.php#L71"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset/3090513"
},
{
"type": "WEB",
"url": "https://wordpress.org/plugins/lastudio-element-kit/#developers"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/6c87204d-6697-4d06-aad2-279fa95f503a?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T04:15:09Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f7vw-6h99-wmxg",
"modified": "2024-05-23T06:30:45Z",
"published": "2024-05-23T06:30:45Z",
"aliases": [
"CVE-2024-2220"
],
"details": "The Button contact VR WordPress plugin through 4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2220"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/fe8c001e-8880-4570-b010-a41fc8ee0c58"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T06:15:08Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fhrg-g7p2-r2f3",
"modified": "2024-05-23T06:30:46Z",
"published": "2024-05-23T06:30:46Z",
"aliases": [
"CVE-2024-5238"
],
"details": "A vulnerability, which was classified as critical, was found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /view/timetable_insert_form.php. The manipulation of the argument grade leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-265989 was assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5238"
},
{
"type": "WEB",
"url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2028.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.265989"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.265989"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.339814"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T06:15:12Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g37v-c843-6cw3",
"modified": "2024-05-23T06:30:45Z",
"published": "2024-05-23T06:30:45Z",
"aliases": [
"CVE-2024-4662"
],
"details": "The Oxygen Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.8.2 via post metadata. This is due to the plugin storing custom data in post metadata without an underscore prefix. This makes it possible for lower privileged users, such as contributors, to inject arbitrary PHP code via the WordPress user interface and gain elevated privileges.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4662"
},
{
"type": "WEB",
"url": "https://oxygenbuilder.com/oxygen-4-8-3-now-available-security-update"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8706c3f6-64e0-440e-a802-5c80d9cc3643?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T05:15:49Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h8c6-6ff8-4h69",
"modified": "2024-05-23T06:30:45Z",
"published": "2024-05-23T06:30:45Z",
"aliases": [
"CVE-2024-5233"
],
"details": "A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /view/teacher_salary_details3.php. The manipulation of the argument index leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-265984.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5233"
},
{
"type": "WEB",
"url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2023.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.265984"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.265984"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.339809"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T05:15:49Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hmvr-jmxq-q9hj",
"modified": "2024-05-23T06:30:45Z",
"published": "2024-05-23T06:30:45Z",
"aliases": [
"CVE-2024-3626"
],
"details": "The Email Subscribers by Icegram Express Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_template_content function in all versions up to, and including, 5.7.17. This makes it possible for authenticated attackers, with subscriber access and above, to obtain the contents of private and password-protected posts.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3626"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/email-subscribers/trunk/lite/admin/class-email-subscribers-admin.php#L849"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/browser/email-subscribers/trunk/lite/includes/class-email-subscribers.php#L1063"
},
{
"type": "WEB",
"url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3072302%40email-subscribers%2Ftrunk&old=3069441%40email-subscribers%2Ftrunk&sfp_email=&sfph_mail="
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5a56e621-2508-4500-b865-4d5e4463b91a?source=cve"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T06:15:10Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hv56-x76m-qpj5",
"modified": "2024-05-23T06:30:45Z",
"published": "2024-05-23T06:30:45Z",
"aliases": [
"CVE-2024-5234"
],
"details": "A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /view/teacher_salary_history1.php. The manipulation of the argument index leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-265985 was assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5234"
},
{
"type": "WEB",
"url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2024.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.265985"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.265985"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.339810"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T05:15:49Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jhvx-96xq-qggm",
"modified": "2024-05-23T06:30:45Z",
"published": "2024-05-23T06:30:45Z",
"aliases": [
"CVE-2024-5236"
],
"details": "A vulnerability classified as critical was found in Campcodes Complete Web-Based School Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view/teacher_salary_invoice1.php. The manipulation of the argument date leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-265987.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5236"
},
{
"type": "WEB",
"url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2026.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.265987"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.265987"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.339812"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T05:15:50Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jj5x-5vg3-9m7f",
"modified": "2024-05-23T06:30:46Z",
"published": "2024-05-23T06:30:46Z",
"aliases": [
"CVE-2024-3920"
],
"details": "The Flattr WordPress plugin through 1.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3920"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/2fb28c77-3c35-4a2f-91ed-823d0d011048"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T06:15:11Z"
}
}
@@ -0,0 +1,50 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m99q-89rr-5mvx",
"modified": "2024-05-23T06:30:45Z",
"published": "2024-05-23T06:30:45Z",
"aliases": [
"CVE-2024-5232"
],
"details": "A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as critical. This affects an unknown part of the file /view/teacher_salary_details2.php. The manipulation of the argument index leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-265983.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5232"
},
{
"type": "WEB",
"url": "https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2022.pdf"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.265983"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.265983"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.339808"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T04:15:09Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p45m-mr9q-rx4p",
"modified": "2024-05-23T06:30:46Z",
"published": "2024-05-23T06:30:46Z",
"aliases": [
"CVE-2024-3918"
],
"details": "The Pet Manager WordPress plugin through 1.4 does not sanitise and escape some of its Pet settings, which could allow high privilege users such as Contributor to perform Stored Cross-Site Scripting attacks.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3918"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/2074d0f5-4165-4130-9391-37cb21e8aa1b"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T06:15:11Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pvgx-v84j-v63h",
"modified": "2024-05-23T06:30:46Z",
"published": "2024-05-23T06:30:46Z",
"aliases": [
"CVE-2024-4388"
],
"details": "This does not validate a path generated with user input when downloading files, allowing unauthenticated user to download arbitrary files from the server",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4388"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/5c791747-f60a-40a7-94fd-e4b9bb5ea2b0"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T06:15:11Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q6fh-vc2v-h383",
"modified": "2024-05-23T06:30:46Z",
"published": "2024-05-23T06:30:46Z",
"aliases": [
"CVE-2024-4399"
],
"details": "The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4399"
},
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/0690327e-da60-4d71-8b3c-ac9533d82302"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-23T06:15:11Z"
}
}

Some files were not shown because too many files have changed in this diff Show More