diff --git a/advisories/unreviewed/2024/10/GHSA-2gvh-vj62-qjmp/GHSA-2gvh-vj62-qjmp.json b/advisories/unreviewed/2024/10/GHSA-2gvh-vj62-qjmp/GHSA-2gvh-vj62-qjmp.json index 826434bb323..0193e5d2521 100644 --- a/advisories/unreviewed/2024/10/GHSA-2gvh-vj62-qjmp/GHSA-2gvh-vj62-qjmp.json +++ b/advisories/unreviewed/2024/10/GHSA-2gvh-vj62-qjmp/GHSA-2gvh-vj62-qjmp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2gvh-vj62-qjmp", - "modified": "2024-12-14T21:31:32Z", + "modified": "2025-01-02T15:31:57Z", "published": "2024-10-21T18:30:58Z", "aliases": [ "CVE-2024-49926" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/3104bddc666ff64b90491868bbc4c7ebdd90aedf" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/acddb87620142f38fda834cd1ec661512ca59241" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/b3b2431ed27f4ebc28e26cdf005c1de42dc60bdf" diff --git a/advisories/unreviewed/2024/11/GHSA-wrcm-3w95-9w36/GHSA-wrcm-3w95-9w36.json b/advisories/unreviewed/2024/11/GHSA-wrcm-3w95-9w36/GHSA-wrcm-3w95-9w36.json index 885fcfdad5d..c1edfd7ca65 100644 --- a/advisories/unreviewed/2024/11/GHSA-wrcm-3w95-9w36/GHSA-wrcm-3w95-9w36.json +++ b/advisories/unreviewed/2024/11/GHSA-wrcm-3w95-9w36/GHSA-wrcm-3w95-9w36.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wrcm-3w95-9w36", - "modified": "2024-11-08T18:30:48Z", + "modified": "2025-01-02T15:31:57Z", "published": "2024-11-05T18:32:12Z", "aliases": [ "CVE-2024-50121" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50121" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/36775f42e039b01d4abe8998bf66771a37d3cdcc" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/add1df5eba163a3a6ece11cb85890e2e410baaea" diff --git a/advisories/unreviewed/2024/11/GHSA-wxqq-8jjm-6pjm/GHSA-wxqq-8jjm-6pjm.json b/advisories/unreviewed/2024/11/GHSA-wxqq-8jjm-6pjm/GHSA-wxqq-8jjm-6pjm.json index 2281c0b7ef1..fa794e17993 100644 --- a/advisories/unreviewed/2024/11/GHSA-wxqq-8jjm-6pjm/GHSA-wxqq-8jjm-6pjm.json +++ b/advisories/unreviewed/2024/11/GHSA-wxqq-8jjm-6pjm/GHSA-wxqq-8jjm-6pjm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wxqq-8jjm-6pjm", - "modified": "2024-11-18T21:30:43Z", + "modified": "2025-01-02T15:31:57Z", "published": "2024-11-07T12:30:34Z", "aliases": [ "CVE-2024-50146" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/4dbc1d1a9f39c3711ad2a40addca04d07d9ab5d0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/db84cb4c8c565e6d4de84b23c2818b63991adfdd" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-xmv6-x39j-72gg/GHSA-xmv6-x39j-72gg.json b/advisories/unreviewed/2024/11/GHSA-xmv6-x39j-72gg/GHSA-xmv6-x39j-72gg.json index 77522a38e99..f3bfb0e57b6 100644 --- a/advisories/unreviewed/2024/11/GHSA-xmv6-x39j-72gg/GHSA-xmv6-x39j-72gg.json +++ b/advisories/unreviewed/2024/11/GHSA-xmv6-x39j-72gg/GHSA-xmv6-x39j-72gg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xmv6-x39j-72gg", - "modified": "2024-12-24T18:30:49Z", + "modified": "2025-01-02T15:31:57Z", "published": "2024-11-26T00:33:31Z", "aliases": [ "CVE-2024-53099" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53099" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e8074bb33d18f56af30a0252cb3606d27eb1c13" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/8421d4c8762bd022cb491f2f0f7019ef51b4f0a7" diff --git a/advisories/unreviewed/2024/12/GHSA-23x3-68r3-3j2p/GHSA-23x3-68r3-3j2p.json b/advisories/unreviewed/2024/12/GHSA-23x3-68r3-3j2p/GHSA-23x3-68r3-3j2p.json index 47d22d2fbb4..21e173013ce 100644 --- a/advisories/unreviewed/2024/12/GHSA-23x3-68r3-3j2p/GHSA-23x3-68r3-3j2p.json +++ b/advisories/unreviewed/2024/12/GHSA-23x3-68r3-3j2p/GHSA-23x3-68r3-3j2p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-23x3-68r3-3j2p", - "modified": "2024-12-13T18:31:55Z", + "modified": "2025-01-02T15:31:57Z", "published": "2024-12-04T15:31:52Z", "aliases": [ "CVE-2024-53128" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53128" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2d2b19ed4169c38dc6c61a186c5f7bdafc709691" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/fbfe23012cec509dfbe09852019c4e4bb84999d0" diff --git a/advisories/unreviewed/2024/12/GHSA-c62g-6hm9-x69q/GHSA-c62g-6hm9-x69q.json b/advisories/unreviewed/2024/12/GHSA-c62g-6hm9-x69q/GHSA-c62g-6hm9-x69q.json index 7cf4012a4f5..1cfab303e31 100644 --- a/advisories/unreviewed/2024/12/GHSA-c62g-6hm9-x69q/GHSA-c62g-6hm9-x69q.json +++ b/advisories/unreviewed/2024/12/GHSA-c62g-6hm9-x69q/GHSA-c62g-6hm9-x69q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c62g-6hm9-x69q", - "modified": "2024-12-29T09:30:46Z", + "modified": "2025-01-02T15:31:57Z", "published": "2024-12-29T09:30:46Z", "aliases": [ "CVE-2024-56710" @@ -14,6 +14,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56710" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/44e518abbb498075ae85c7d1d1a503a6bb05ea2d" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/66e0c4f91461d17d48071695271c824620bed4ef" diff --git a/advisories/unreviewed/2025/01/GHSA-322v-gpc6-pf9f/GHSA-322v-gpc6-pf9f.json b/advisories/unreviewed/2025/01/GHSA-322v-gpc6-pf9f/GHSA-322v-gpc6-pf9f.json new file mode 100644 index 00000000000..e97b4e3247b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-322v-gpc6-pf9f/GHSA-322v-gpc6-pf9f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-322v-gpc6-pf9f", + "modified": "2025-01-02T15:31:59Z", + "published": "2025-01-02T15:31:59Z", + "aliases": [ + "CVE-2024-49385" + ], + "details": "Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 41736.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49385" + }, + { + "type": "WEB", + "url": "https://security-advisory.acronis.com/advisories/SEC-2397" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-44cf-cppv-qcvq/GHSA-44cf-cppv-qcvq.json b/advisories/unreviewed/2025/01/GHSA-44cf-cppv-qcvq/GHSA-44cf-cppv-qcvq.json new file mode 100644 index 00000000000..f24a8faa78e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-44cf-cppv-qcvq/GHSA-44cf-cppv-qcvq.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44cf-cppv-qcvq", + "modified": "2025-01-02T15:31:57Z", + "published": "2025-01-02T15:31:57Z", + "aliases": [ + "CVE-2024-13108" + ], + "details": "A vulnerability was found in D-Link DIR-816 A2 1.10CNB05_R1B011D88210. It has been declared as critical. This vulnerability affects unknown code of the file /goform/form2NetSniper.cgi. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13108" + }, + { + "type": "WEB", + "url": "https://github.com/abcdefg-png/IoT-vulnerable/blob/main/Unauthorized_Vulnerability/D-Link/DIR-816/form2NetSniper.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289924" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289924" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.472088" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-46v9-776w-chff/GHSA-46v9-776w-chff.json b/advisories/unreviewed/2025/01/GHSA-46v9-776w-chff/GHSA-46v9-776w-chff.json new file mode 100644 index 00000000000..fed6895f624 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-46v9-776w-chff/GHSA-46v9-776w-chff.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-46v9-776w-chff", + "modified": "2025-01-02T15:31:57Z", + "published": "2025-01-02T15:31:57Z", + "aliases": [ + "CVE-2024-39623" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in CridioStudio ListingPro allows Authentication Bypass.This issue affects ListingPro: from n/a through 2.9.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39623" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/listingpro/vulnerability/wordpress-listingpro-theme-2-9-3-cross-site-request-forgery-csrf-to-account-takeover-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5vxr-73wh-94hw/GHSA-5vxr-73wh-94hw.json b/advisories/unreviewed/2025/01/GHSA-5vxr-73wh-94hw/GHSA-5vxr-73wh-94hw.json new file mode 100644 index 00000000000..83653575bf0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5vxr-73wh-94hw/GHSA-5vxr-73wh-94hw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vxr-73wh-94hw", + "modified": "2025-01-02T15:31:59Z", + "published": "2025-01-02T15:31:59Z", + "aliases": [ + "CVE-2023-40327" + ], + "details": "Missing Authorization vulnerability in Putler / Storeapps Putler Connector for WooCommerce.This issue affects Putler Connector for WooCommerce: from n/a through 2.12.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40327" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woocommerce-putler-connector/vulnerability/wordpress-putler-connector-for-woocommerce-plugin-2-12-0-unauthenticated-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-659r-6ccr-7pp8/GHSA-659r-6ccr-7pp8.json b/advisories/unreviewed/2025/01/GHSA-659r-6ccr-7pp8/GHSA-659r-6ccr-7pp8.json new file mode 100644 index 00000000000..49f814fa6fd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-659r-6ccr-7pp8/GHSA-659r-6ccr-7pp8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-659r-6ccr-7pp8", + "modified": "2025-01-02T15:31:59Z", + "published": "2025-01-02T15:31:59Z", + "aliases": [ + "CVE-2023-48739" + ], + "details": "Missing Authorization vulnerability in Porto Theme Porto Theme - Functionality allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Porto Theme - Functionality: from n/a before 2.12.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48739" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/porto-functionality/vulnerability/wordpress-porto-theme-functionality-plugin-2-11-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6crw-h5cj-4wrx/GHSA-6crw-h5cj-4wrx.json b/advisories/unreviewed/2025/01/GHSA-6crw-h5cj-4wrx/GHSA-6crw-h5cj-4wrx.json new file mode 100644 index 00000000000..ad21df5edfb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6crw-h5cj-4wrx/GHSA-6crw-h5cj-4wrx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6crw-h5cj-4wrx", + "modified": "2025-01-02T15:31:58Z", + "published": "2025-01-02T15:31:58Z", + "aliases": [ + "CVE-2024-37438" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Toolkit Pro for LearnDash allows Cross Site Request Forgery.This issue affects Uncanny Toolkit Pro for LearnDash: from n/a before 4.1.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37438" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/uncanny-toolkit-pro/vulnerability/wordpress-uncanny-toolkit-pro-for-learndash-plugin-4-1-4-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7wfm-8v5r-vhv5/GHSA-7wfm-8v5r-vhv5.json b/advisories/unreviewed/2025/01/GHSA-7wfm-8v5r-vhv5/GHSA-7wfm-8v5r-vhv5.json new file mode 100644 index 00000000000..4ec3ff7abd2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7wfm-8v5r-vhv5/GHSA-7wfm-8v5r-vhv5.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wfm-8v5r-vhv5", + "modified": "2025-01-02T15:31:58Z", + "published": "2025-01-02T15:31:58Z", + "aliases": [ + "CVE-2024-13110" + ], + "details": "A vulnerability classified as problematic has been found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected is an unknown function of the file src/main/java/com/yf/exam/modules/paper/controller/PaperController.java, of the component Exam Answer Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13110" + }, + { + "type": "WEB", + "url": "https://github.com/qiutiandefeng/yfexam-exam/issues/5" + }, + { + "type": "WEB", + "url": "https://github.com/qiutiandefeng/yfexam-exam/issues/5#issue-2754675223" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289926" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289926" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.467700" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7xgj-vh96-453m/GHSA-7xgj-vh96-453m.json b/advisories/unreviewed/2025/01/GHSA-7xgj-vh96-453m/GHSA-7xgj-vh96-453m.json new file mode 100644 index 00000000000..acf84eda005 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7xgj-vh96-453m/GHSA-7xgj-vh96-453m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xgj-vh96-453m", + "modified": "2025-01-02T15:31:59Z", + "published": "2025-01-02T15:31:59Z", + "aliases": [ + "CVE-2023-45633" + ], + "details": "Missing Authorization vulnerability in IDX IMPress Listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IMPress Listings: from n/a through 2.6.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45633" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-listings/vulnerability/wordpress-impress-listings-plugin-2-6-2-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8322-9v37-rr6q/GHSA-8322-9v37-rr6q.json b/advisories/unreviewed/2025/01/GHSA-8322-9v37-rr6q/GHSA-8322-9v37-rr6q.json new file mode 100644 index 00000000000..25095b728e5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8322-9v37-rr6q/GHSA-8322-9v37-rr6q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8322-9v37-rr6q", + "modified": "2025-01-02T15:31:57Z", + "published": "2025-01-02T15:31:57Z", + "aliases": [ + "CVE-2024-56268" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Hait Post Grid Elementor Addon allows Stored XSS.This issue affects Post Grid Elementor Addon: from n/a through 2.0.18.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56268" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/post-grid-elementor-addon/vulnerability/wordpress-post-grid-elementor-addon-plugin-2-0-18-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8mmw-w2v8-xq87/GHSA-8mmw-w2v8-xq87.json b/advisories/unreviewed/2025/01/GHSA-8mmw-w2v8-xq87/GHSA-8mmw-w2v8-xq87.json new file mode 100644 index 00000000000..ec5080f0871 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8mmw-w2v8-xq87/GHSA-8mmw-w2v8-xq87.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mmw-w2v8-xq87", + "modified": "2025-01-02T15:31:57Z", + "published": "2025-01-02T15:31:57Z", + "aliases": [ + "CVE-2024-56257" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CoolPlugins Coins MarketCap allows DOM-Based XSS.This issue affects Coins MarketCap: from n/a through 5.5.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56257" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/coins-marketcap/vulnerability/wordpress-coins-marketcap-plugin-5-5-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8r8h-hr7m-2258/GHSA-8r8h-hr7m-2258.json b/advisories/unreviewed/2025/01/GHSA-8r8h-hr7m-2258/GHSA-8r8h-hr7m-2258.json new file mode 100644 index 00000000000..1797a8632d6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8r8h-hr7m-2258/GHSA-8r8h-hr7m-2258.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r8h-hr7m-2258", + "modified": "2025-01-02T15:31:58Z", + "published": "2025-01-02T15:31:58Z", + "aliases": [ + "CVE-2024-37241" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Automattic WP Job Manager - Resume Manager allows Cross Site Request Forgery.This issue affects WP Job Manager - Resume Manager: from n/a through 2.1.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37241" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-job-manager-resumes/vulnerability/wordpress-wp-job-manager-resume-manager-plugin-2-1-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9c7x-gvxw-8jhq/GHSA-9c7x-gvxw-8jhq.json b/advisories/unreviewed/2025/01/GHSA-9c7x-gvxw-8jhq/GHSA-9c7x-gvxw-8jhq.json new file mode 100644 index 00000000000..2903c0d7887 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9c7x-gvxw-8jhq/GHSA-9c7x-gvxw-8jhq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9c7x-gvxw-8jhq", + "modified": "2025-01-02T15:31:59Z", + "published": "2025-01-02T15:31:59Z", + "aliases": [ + "CVE-2023-47778" + ], + "details": "Missing Authorization vulnerability in LuckyWP LuckyWP Scripts Control allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LuckyWP Scripts Control: from n/a through 1.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47778" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/luckywp-scripts-control/vulnerability/wordpress-luckywp-scripts-control-plugin-1-2-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9fxm-qh6m-23f8/GHSA-9fxm-qh6m-23f8.json b/advisories/unreviewed/2025/01/GHSA-9fxm-qh6m-23f8/GHSA-9fxm-qh6m-23f8.json new file mode 100644 index 00000000000..e9dd86b3a44 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9fxm-qh6m-23f8/GHSA-9fxm-qh6m-23f8.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fxm-qh6m-23f8", + "modified": "2025-01-02T15:31:59Z", + "published": "2025-01-02T15:31:59Z", + "aliases": [ + "CVE-2022-49035" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: s5p_cec: limit msg.len to CEC_MAX_MSG_SIZE\n\nI expect that the hardware will have limited this to 16, but just in\ncase it hasn't, check for this corner case.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49035" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1609231f86760c1f6a429de7913dd795b9faa08c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2654e785bd4aa2439cdffbe7dc1ea30a0eddbfe4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4a449430ecfb199b99ba58af63c467eb53500b39" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7ccb40f26cbefa1c6dfd3418bea54c9518cdbd8a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/93f65ce036863893c164ca410938e0968964b26c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a2728bf9b6c65e46468c763e3dab7e04839d4e11" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cbfa26936f318b16ccf9ca31b8e8b30c0dc087bd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fc0f76dd5f116fa9291327024dda392f8b4e849c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9qwx-qvm3-h6gg/GHSA-9qwx-qvm3-h6gg.json b/advisories/unreviewed/2025/01/GHSA-9qwx-qvm3-h6gg/GHSA-9qwx-qvm3-h6gg.json new file mode 100644 index 00000000000..c97f3691584 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9qwx-qvm3-h6gg/GHSA-9qwx-qvm3-h6gg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qwx-qvm3-h6gg", + "modified": "2025-01-02T15:31:58Z", + "published": "2025-01-02T15:31:58Z", + "aliases": [ + "CVE-2022-45830" + ], + "details": "Missing Authorization vulnerability in Analytify.This issue affects Analytify: from n/a through 4.2.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45830" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-analytify/vulnerability/wordpress-analytify-google-analytics-dashboard-plugin-4-2-3-privilege-escalation?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9vhg-5pgx-8q97/GHSA-9vhg-5pgx-8q97.json b/advisories/unreviewed/2025/01/GHSA-9vhg-5pgx-8q97/GHSA-9vhg-5pgx-8q97.json new file mode 100644 index 00000000000..f1cc19daed0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9vhg-5pgx-8q97/GHSA-9vhg-5pgx-8q97.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vhg-5pgx-8q97", + "modified": "2025-01-02T15:31:58Z", + "published": "2025-01-02T15:31:58Z", + "aliases": [ + "CVE-2024-13111" + ], + "details": "A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected by this vulnerability is an unknown functionality of the file src/main/java/com/yf/exam/modules/sys/user/controller/SysUserControl of the component JWT Token Handler. The manipulation leads to improper authentication. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13111" + }, + { + "type": "WEB", + "url": "https://github.com/qiutiandefeng/yfexam-exam/issues/6" + }, + { + "type": "WEB", + "url": "https://github.com/qiutiandefeng/yfexam-exam/issues/6#issue-2754680012" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289927" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289927" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.467701" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c3h4-65wr-9pqr/GHSA-c3h4-65wr-9pqr.json b/advisories/unreviewed/2025/01/GHSA-c3h4-65wr-9pqr/GHSA-c3h4-65wr-9pqr.json new file mode 100644 index 00000000000..07d27fb98e9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c3h4-65wr-9pqr/GHSA-c3h4-65wr-9pqr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3h4-65wr-9pqr", + "modified": "2025-01-02T15:31:58Z", + "published": "2025-01-02T15:31:57Z", + "aliases": [ + "CVE-2024-37237" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in FS-code FS Poster allows Cross Site Request Forgery.This issue affects FS Poster: from n/a through 6.5.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37237" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fs-poster/vulnerability/wordpress-fs-poster-plugin-6-5-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-ffqr-4qwv-gwp9/GHSA-ffqr-4qwv-gwp9.json b/advisories/unreviewed/2025/01/GHSA-ffqr-4qwv-gwp9/GHSA-ffqr-4qwv-gwp9.json new file mode 100644 index 00000000000..6670ef0baa1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-ffqr-4qwv-gwp9/GHSA-ffqr-4qwv-gwp9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffqr-4qwv-gwp9", + "modified": "2025-01-02T15:31:59Z", + "published": "2025-01-02T15:31:59Z", + "aliases": [ + "CVE-2023-39994" + ], + "details": "Missing Authorization vulnerability in Repute InfoSystems ARMember Premium allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ARMember Premium: from n/a through 5.9.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-39994" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/armember/vulnerability/wordpress-armember-premium-wordpress-membership-plugin-plugin-5-9-2-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fg46-5wmx-p2gg/GHSA-fg46-5wmx-p2gg.json b/advisories/unreviewed/2025/01/GHSA-fg46-5wmx-p2gg/GHSA-fg46-5wmx-p2gg.json new file mode 100644 index 00000000000..8d7d827ddd6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fg46-5wmx-p2gg/GHSA-fg46-5wmx-p2gg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg46-5wmx-p2gg", + "modified": "2025-01-02T15:31:58Z", + "published": "2025-01-02T15:31:58Z", + "aliases": [ + "CVE-2024-38732" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in VolThemes Patricia Blog allows Cross Site Request Forgery.This issue affects Patricia Blog: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38732" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/patricia-blog/vulnerability/wordpress-patricia-blog-theme-1-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fxqr-8c9h-vpmp/GHSA-fxqr-8c9h-vpmp.json b/advisories/unreviewed/2025/01/GHSA-fxqr-8c9h-vpmp/GHSA-fxqr-8c9h-vpmp.json new file mode 100644 index 00000000000..2e1e11dfb94 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fxqr-8c9h-vpmp/GHSA-fxqr-8c9h-vpmp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxqr-8c9h-vpmp", + "modified": "2025-01-02T15:31:57Z", + "published": "2025-01-02T15:31:57Z", + "aliases": [ + "CVE-2024-38764" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Marsian allows Cross Site Request Forgery.This issue affects i-transform: from n/a through 3.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38764" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/i-transform/vulnerability/wordpress-i-transform-theme-3-0-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gccm-257v-26xf/GHSA-gccm-257v-26xf.json b/advisories/unreviewed/2025/01/GHSA-gccm-257v-26xf/GHSA-gccm-257v-26xf.json new file mode 100644 index 00000000000..59b8ea5b8f4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gccm-257v-26xf/GHSA-gccm-257v-26xf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gccm-257v-26xf", + "modified": "2025-01-02T15:31:59Z", + "published": "2025-01-02T15:31:59Z", + "aliases": [ + "CVE-2023-32240" + ], + "details": "Missing Authorization vulnerability in Xtemos WoodMart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WoodMart: from n/a through 7.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32240" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/woodmart/vulnerability/wordpress-woodmart-theme-7-2-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j27q-8m9v-cph3/GHSA-j27q-8m9v-cph3.json b/advisories/unreviewed/2025/01/GHSA-j27q-8m9v-cph3/GHSA-j27q-8m9v-cph3.json new file mode 100644 index 00000000000..197ca83d23c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j27q-8m9v-cph3/GHSA-j27q-8m9v-cph3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j27q-8m9v-cph3", + "modified": "2025-01-02T15:31:58Z", + "published": "2025-01-02T15:31:58Z", + "aliases": [ + "CVE-2024-37931" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Creativthemes Point allows Cross Site Request Forgery.This issue affects Point: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37931" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/point/vulnerability/wordpress-point-theme-1-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j8mp-8grf-469r/GHSA-j8mp-8grf-469r.json b/advisories/unreviewed/2025/01/GHSA-j8mp-8grf-469r/GHSA-j8mp-8grf-469r.json new file mode 100644 index 00000000000..d46504db804 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j8mp-8grf-469r/GHSA-j8mp-8grf-469r.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8mp-8grf-469r", + "modified": "2025-01-02T15:31:59Z", + "published": "2025-01-02T15:31:59Z", + "aliases": [ + "CVE-2025-0171" + ], + "details": "A vulnerability, which was classified as critical, was found in code-projects Chat System 1.0. Affected is an unknown function of the file /admin/deleteuser.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0171" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/Sinon2003/cve/blob/main/sql_inject1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289938" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289938" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.473143" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T15:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jp88-cx84-jjj5/GHSA-jp88-cx84-jjj5.json b/advisories/unreviewed/2025/01/GHSA-jp88-cx84-jjj5/GHSA-jp88-cx84-jjj5.json new file mode 100644 index 00000000000..4e7f56f9818 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jp88-cx84-jjj5/GHSA-jp88-cx84-jjj5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jp88-cx84-jjj5", + "modified": "2025-01-02T15:31:58Z", + "published": "2025-01-02T15:31:58Z", + "aliases": [ + "CVE-2024-38731" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Marsian i-amaze allows Cross Site Request Forgery.This issue affects i-amaze: from n/a through 1.3.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38731" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/i-amaze/vulnerability/wordpress-i-amaze-theme-1-3-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m584-jg3p-v35g/GHSA-m584-jg3p-v35g.json b/advisories/unreviewed/2025/01/GHSA-m584-jg3p-v35g/GHSA-m584-jg3p-v35g.json new file mode 100644 index 00000000000..5404b4e69fd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m584-jg3p-v35g/GHSA-m584-jg3p-v35g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m584-jg3p-v35g", + "modified": "2025-01-02T15:31:58Z", + "published": "2025-01-02T15:31:58Z", + "aliases": [ + "CVE-2024-37925" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in BUDDYBOSS LLC BuddyBoss Theme allows Cross Site Request Forgery.This issue affects BuddyBoss Theme: from n/a through 2.4.61.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37925" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/buddyboss-theme/vulnerability/wordpress-buddyboss-theme-theme-2-4-61-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mhhp-32w8-cvw6/GHSA-mhhp-32w8-cvw6.json b/advisories/unreviewed/2025/01/GHSA-mhhp-32w8-cvw6/GHSA-mhhp-32w8-cvw6.json new file mode 100644 index 00000000000..6300363a3fd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mhhp-32w8-cvw6/GHSA-mhhp-32w8-cvw6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhhp-32w8-cvw6", + "modified": "2025-01-02T15:31:57Z", + "published": "2025-01-02T15:31:57Z", + "aliases": [ + "CVE-2024-56014" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markyis Cool Olivia allows Reflected XSS.This issue affects Olivia: from n/a through 0.9.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56014" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/olivia/vulnerability/wordpress-olivia-theme-0-9-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qcr9-xmgh-hrcw/GHSA-qcr9-xmgh-hrcw.json b/advisories/unreviewed/2025/01/GHSA-qcr9-xmgh-hrcw/GHSA-qcr9-xmgh-hrcw.json new file mode 100644 index 00000000000..d73669af204 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qcr9-xmgh-hrcw/GHSA-qcr9-xmgh-hrcw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcr9-xmgh-hrcw", + "modified": "2025-01-02T15:31:58Z", + "published": "2025-01-02T15:31:58Z", + "aliases": [ + "CVE-2024-37452" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop Schema Lite allows Cross Site Request Forgery.This issue affects Schema Lite: from n/a through 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37452" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/theme/schema-lite/vulnerability/wordpress-schema-lite-theme-1-2-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qpgp-454m-6h35/GHSA-qpgp-454m-6h35.json b/advisories/unreviewed/2025/01/GHSA-qpgp-454m-6h35/GHSA-qpgp-454m-6h35.json new file mode 100644 index 00000000000..3073d58f5c7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qpgp-454m-6h35/GHSA-qpgp-454m-6h35.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpgp-454m-6h35", + "modified": "2025-01-02T15:31:59Z", + "published": "2025-01-02T15:31:59Z", + "aliases": [ + "CVE-2023-45272" + ], + "details": "Missing Authorization vulnerability in 10Web 10Web Map Builder for Google Maps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 10Web Map Builder for Google Maps: from n/a through 1.0.73.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45272" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wd-google-maps/vulnerability/wordpress-10web-map-builder-for-google-maps-plugin-1-0-73-notice-dismissal-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vj84-g42v-754m/GHSA-vj84-g42v-754m.json b/advisories/unreviewed/2025/01/GHSA-vj84-g42v-754m/GHSA-vj84-g42v-754m.json new file mode 100644 index 00000000000..afdff2ed7f2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vj84-g42v-754m/GHSA-vj84-g42v-754m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vj84-g42v-754m", + "modified": "2025-01-02T15:31:59Z", + "published": "2025-01-02T15:31:59Z", + "aliases": [ + "CVE-2023-48758" + ], + "details": "Missing Authorization vulnerability in Crocoblock JetEngine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through 3.2.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48758" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/jet-engine/vulnerability/wordpress-jetengine-plugin-3-2-4-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T15:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vmvq-fh49-9m4q/GHSA-vmvq-fh49-9m4q.json b/advisories/unreviewed/2025/01/GHSA-vmvq-fh49-9m4q/GHSA-vmvq-fh49-9m4q.json new file mode 100644 index 00000000000..af3b7f9fe61 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vmvq-fh49-9m4q/GHSA-vmvq-fh49-9m4q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmvq-fh49-9m4q", + "modified": "2025-01-02T15:31:58Z", + "published": "2025-01-02T15:31:58Z", + "aliases": [ + "CVE-2022-41995" + ], + "details": "Missing Authorization vulnerability in Galleryape Gallery Images Ape allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gallery Images Ape: from n/a through 2.2.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41995" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/gallery-images-ape/vulnerability/wordpress-gallery-images-ape-plugin-2-2-8-auth-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vwm8-49xh-7phm/GHSA-vwm8-49xh-7phm.json b/advisories/unreviewed/2025/01/GHSA-vwm8-49xh-7phm/GHSA-vwm8-49xh-7phm.json new file mode 100644 index 00000000000..0602a84f062 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vwm8-49xh-7phm/GHSA-vwm8-49xh-7phm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vwm8-49xh-7phm", + "modified": "2025-01-02T15:31:57Z", + "published": "2025-01-02T15:31:57Z", + "aliases": [ + "CVE-2024-38778" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search.This issue affects WP Fast Total Search: from n/a through 1.69.234.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38778" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/fulltext-search/vulnerability/wordpress-wp-fast-total-search-1-69-234-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w626-5585-3jv3/GHSA-w626-5585-3jv3.json b/advisories/unreviewed/2025/01/GHSA-w626-5585-3jv3/GHSA-w626-5585-3jv3.json new file mode 100644 index 00000000000..1d9038d91ce --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w626-5585-3jv3/GHSA-w626-5585-3jv3.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w626-5585-3jv3", + "modified": "2025-01-02T15:31:57Z", + "published": "2025-01-02T15:31:57Z", + "aliases": [ + "CVE-2024-13109" + ], + "details": "A vulnerability was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. It has been rated as critical. This issue affects some unknown processing of the file /doc.html. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13109" + }, + { + "type": "WEB", + "url": "https://github.com/qiutiandefeng/yfexam-exam/issues/4" + }, + { + "type": "WEB", + "url": "https://github.com/qiutiandefeng/yfexam-exam/issues/4#issue-2754670219" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289925" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289925" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.467695" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T13:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wjv5-m9xx-wpj6/GHSA-wjv5-m9xx-wpj6.json b/advisories/unreviewed/2025/01/GHSA-wjv5-m9xx-wpj6/GHSA-wjv5-m9xx-wpj6.json new file mode 100644 index 00000000000..787ad479845 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wjv5-m9xx-wpj6/GHSA-wjv5-m9xx-wpj6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjv5-m9xx-wpj6", + "modified": "2025-01-02T15:31:59Z", + "published": "2025-01-02T15:31:59Z", + "aliases": [ + "CVE-2024-55538" + ], + "details": "Sensitive information disclosure due to missing authentication. The following products are affected: Acronis True Image (macOS) before build 41725, Acronis True Image (Windows) before build 41736.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55538" + }, + { + "type": "WEB", + "url": "https://security-advisory.acronis.com/advisories/SEC-2209" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T15:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x9ph-j5w6-gjmf/GHSA-x9ph-j5w6-gjmf.json b/advisories/unreviewed/2025/01/GHSA-x9ph-j5w6-gjmf/GHSA-x9ph-j5w6-gjmf.json new file mode 100644 index 00000000000..d5f761f1a72 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x9ph-j5w6-gjmf/GHSA-x9ph-j5w6-gjmf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9ph-j5w6-gjmf", + "modified": "2025-01-02T15:31:58Z", + "published": "2025-01-02T15:31:58Z", + "aliases": [ + "CVE-2022-43476" + ], + "details": "Missing Authorization vulnerability in Daniel Söderström / Sidney van de Stouwe Subscribe to Category allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscribe to Category: from n/a through 2.7.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43476" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/subscribe-to-category/vulnerability/wordpress-subscribe-to-category-plugin-2-7-1-auth-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T15:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xq8f-72xr-vw5q/GHSA-xq8f-72xr-vw5q.json b/advisories/unreviewed/2025/01/GHSA-xq8f-72xr-vw5q/GHSA-xq8f-72xr-vw5q.json new file mode 100644 index 00000000000..93ee89c49cf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xq8f-72xr-vw5q/GHSA-xq8f-72xr-vw5q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xq8f-72xr-vw5q", + "modified": "2025-01-02T15:31:59Z", + "published": "2025-01-02T15:31:59Z", + "aliases": [ + "CVE-2023-47807" + ], + "details": "Missing Authorization vulnerability in 10Web 10WebAnalytics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 10WebAnalytics: from n/a through 1.2.12.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47807" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wd-google-analytics/vulnerability/wordpress-10webanalytics-plugin-1-2-12-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-02T15:15:20Z" + } +} \ No newline at end of file