From da65dfa8a1105931d837e6cd22b355e38e02fecb Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 15 Oct 2024 15:31:55 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-6q6r-hx29-59m5.json | 11 +++- .../GHSA-373g-hg3v-qf78.json | 1 + .../GHSA-436p-pp82-ppwq.json | 1 + .../GHSA-76vg-grjj-w595.json | 1 + .../GHSA-jhh2-7qpr-2pv5.json | 1 + .../GHSA-27vg-qjpq-w479.json | 2 +- .../GHSA-37wv-xpm8-wf7h.json | 2 +- .../GHSA-3wg5-x88w-52fj.json | 7 ++- .../GHSA-3x4w-v43m-f5m7.json | 2 +- .../GHSA-47ww-vfc5-5gxw.json | 2 +- .../GHSA-537j-q568-qwrw.json | 2 +- .../GHSA-53m6-g2mp-6mj7.json | 1 + .../GHSA-55qg-f678-jcg9.json | 35 +++++++++++ .../GHSA-5645-gr78-qx8w.json | 3 +- .../GHSA-6jgw-rgmm-7cv6.json | 54 +++++++++++++++++ .../GHSA-6rfh-8xcw-f6f2.json | 35 +++++++++++ .../GHSA-75jw-84pf-jxc9.json | 35 +++++++++++ .../GHSA-79v4-xhfm-cr97.json | 2 +- .../GHSA-994f-pcw4-m52m.json | 35 +++++++++++ .../GHSA-9f2c-45xq-c486.json | 6 +- .../GHSA-cpxc-2w9f-g929.json | 1 + .../GHSA-fc9h-whq2-v747.json | 39 +++++++++++++ .../GHSA-fpxg-3hxf-5mvr.json | 2 +- .../GHSA-gc35-q76c-xj63.json | 2 +- .../GHSA-gjm5-824v-4vq3.json | 2 +- .../GHSA-h2fm-p5xw-r67q.json | 2 +- .../GHSA-h8v4-hc3c-vf8p.json | 6 +- .../GHSA-m36f-v9qc-f9h5.json | 9 ++- .../GHSA-pcmx-c2wg-899q.json | 2 +- .../GHSA-pggm-8jq8-xmxw.json | 54 +++++++++++++++++ .../GHSA-qh35-4qrq-2527.json | 3 +- .../GHSA-r2fh-mj7f-v33r.json | 6 +- .../GHSA-r7wf-fpff-w68q.json | 6 +- .../GHSA-v4pc-7q3f-7vf2.json | 2 +- .../GHSA-vgrm-w974-j729.json | 35 +++++++++++ .../GHSA-w25r-358w-353h.json | 2 +- .../GHSA-wqr7-r7h2-v2j2.json | 58 +++++++++++++++++++ 37 files changed, 445 insertions(+), 24 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-55qg-f678-jcg9/GHSA-55qg-f678-jcg9.json create mode 100644 advisories/unreviewed/2024/10/GHSA-6jgw-rgmm-7cv6/GHSA-6jgw-rgmm-7cv6.json create mode 100644 advisories/unreviewed/2024/10/GHSA-6rfh-8xcw-f6f2/GHSA-6rfh-8xcw-f6f2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-75jw-84pf-jxc9/GHSA-75jw-84pf-jxc9.json create mode 100644 advisories/unreviewed/2024/10/GHSA-994f-pcw4-m52m/GHSA-994f-pcw4-m52m.json create mode 100644 advisories/unreviewed/2024/10/GHSA-fc9h-whq2-v747/GHSA-fc9h-whq2-v747.json create mode 100644 advisories/unreviewed/2024/10/GHSA-pggm-8jq8-xmxw/GHSA-pggm-8jq8-xmxw.json create mode 100644 advisories/unreviewed/2024/10/GHSA-vgrm-w974-j729/GHSA-vgrm-w974-j729.json create mode 100644 advisories/unreviewed/2024/10/GHSA-wqr7-r7h2-v2j2/GHSA-wqr7-r7h2-v2j2.json diff --git a/advisories/unreviewed/2023/09/GHSA-6q6r-hx29-59m5/GHSA-6q6r-hx29-59m5.json b/advisories/unreviewed/2023/09/GHSA-6q6r-hx29-59m5/GHSA-6q6r-hx29-59m5.json index 26d8adbb059..af368df38ef 100644 --- a/advisories/unreviewed/2023/09/GHSA-6q6r-hx29-59m5/GHSA-6q6r-hx29-59m5.json +++ b/advisories/unreviewed/2023/09/GHSA-6q6r-hx29-59m5/GHSA-6q6r-hx29-59m5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6q6r-hx29-59m5", - "modified": "2024-10-15T12:30:35Z", + "modified": "2024-10-15T15:30:44Z", "published": "2023-09-20T09:30:22Z", "aliases": [ "CVE-2023-22644" @@ -21,6 +21,10 @@ ], "references": [ + { + "type": "WEB", + "url": "https://github.com/neuvector/neuvector/security/advisories/GHSA-622h-h2p8-743x" + }, { "type": "WEB", "url": "https://github.com/rancher/rancher/security/advisories/GHSA-9ghh-mmcq-8phc" @@ -36,10 +40,15 @@ { "type": "WEB", "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-22650" + }, + { + "type": "WEB", + "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-32188" } ], "database_specific": { "cwe_ids": [ + "CWE-1270", "CWE-287", "CWE-532" ], diff --git a/advisories/unreviewed/2024/08/GHSA-373g-hg3v-qf78/GHSA-373g-hg3v-qf78.json b/advisories/unreviewed/2024/08/GHSA-373g-hg3v-qf78/GHSA-373g-hg3v-qf78.json index f114318fd30..27b8a817abb 100644 --- a/advisories/unreviewed/2024/08/GHSA-373g-hg3v-qf78/GHSA-373g-hg3v-qf78.json +++ b/advisories/unreviewed/2024/08/GHSA-373g-hg3v-qf78/GHSA-373g-hg3v-qf78.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-122", "CWE-787" ], diff --git a/advisories/unreviewed/2024/08/GHSA-436p-pp82-ppwq/GHSA-436p-pp82-ppwq.json b/advisories/unreviewed/2024/08/GHSA-436p-pp82-ppwq/GHSA-436p-pp82-ppwq.json index 9539c125807..82dd2b96b39 100644 --- a/advisories/unreviewed/2024/08/GHSA-436p-pp82-ppwq/GHSA-436p-pp82-ppwq.json +++ b/advisories/unreviewed/2024/08/GHSA-436p-pp82-ppwq/GHSA-436p-pp82-ppwq.json @@ -36,6 +36,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-121", "CWE-787" ], diff --git a/advisories/unreviewed/2024/08/GHSA-76vg-grjj-w595/GHSA-76vg-grjj-w595.json b/advisories/unreviewed/2024/08/GHSA-76vg-grjj-w595/GHSA-76vg-grjj-w595.json index 40655b3ff82..26a3f888b68 100644 --- a/advisories/unreviewed/2024/08/GHSA-76vg-grjj-w595/GHSA-76vg-grjj-w595.json +++ b/advisories/unreviewed/2024/08/GHSA-76vg-grjj-w595/GHSA-76vg-grjj-w595.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-122", "CWE-787" ], diff --git a/advisories/unreviewed/2024/09/GHSA-jhh2-7qpr-2pv5/GHSA-jhh2-7qpr-2pv5.json b/advisories/unreviewed/2024/09/GHSA-jhh2-7qpr-2pv5/GHSA-jhh2-7qpr-2pv5.json index 3ca696cc208..79350cd06d8 100644 --- a/advisories/unreviewed/2024/09/GHSA-jhh2-7qpr-2pv5/GHSA-jhh2-7qpr-2pv5.json +++ b/advisories/unreviewed/2024/09/GHSA-jhh2-7qpr-2pv5/GHSA-jhh2-7qpr-2pv5.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-121", "CWE-787" ], diff --git a/advisories/unreviewed/2024/10/GHSA-27vg-qjpq-w479/GHSA-27vg-qjpq-w479.json b/advisories/unreviewed/2024/10/GHSA-27vg-qjpq-w479/GHSA-27vg-qjpq-w479.json index 602fd4c1d29..4affc28727a 100644 --- a/advisories/unreviewed/2024/10/GHSA-27vg-qjpq-w479/GHSA-27vg-qjpq-w479.json +++ b/advisories/unreviewed/2024/10/GHSA-27vg-qjpq-w479/GHSA-27vg-qjpq-w479.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-27vg-qjpq-w479", - "modified": "2024-10-10T03:30:45Z", + "modified": "2024-10-15T15:30:45Z", "published": "2024-10-10T03:30:45Z", "aliases": [ "CVE-2024-8987" diff --git a/advisories/unreviewed/2024/10/GHSA-37wv-xpm8-wf7h/GHSA-37wv-xpm8-wf7h.json b/advisories/unreviewed/2024/10/GHSA-37wv-xpm8-wf7h/GHSA-37wv-xpm8-wf7h.json index eff648bca48..6d3aac0f119 100644 --- a/advisories/unreviewed/2024/10/GHSA-37wv-xpm8-wf7h/GHSA-37wv-xpm8-wf7h.json +++ b/advisories/unreviewed/2024/10/GHSA-37wv-xpm8-wf7h/GHSA-37wv-xpm8-wf7h.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-3wg5-x88w-52fj/GHSA-3wg5-x88w-52fj.json b/advisories/unreviewed/2024/10/GHSA-3wg5-x88w-52fj/GHSA-3wg5-x88w-52fj.json index ac280ecbf9f..5bdd2c8b295 100644 --- a/advisories/unreviewed/2024/10/GHSA-3wg5-x88w-52fj/GHSA-3wg5-x88w-52fj.json +++ b/advisories/unreviewed/2024/10/GHSA-3wg5-x88w-52fj/GHSA-3wg5-x88w-52fj.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3wg5-x88w-52fj", - "modified": "2024-10-09T18:31:43Z", + "modified": "2024-10-15T15:30:45Z", "published": "2024-10-09T18:31:43Z", "aliases": [ "CVE-2024-9466" ], "details": "A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red" @@ -28,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-312", "CWE-532" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/10/GHSA-3x4w-v43m-f5m7/GHSA-3x4w-v43m-f5m7.json b/advisories/unreviewed/2024/10/GHSA-3x4w-v43m-f5m7/GHSA-3x4w-v43m-f5m7.json index 805bd21da14..fcdb29c57f5 100644 --- a/advisories/unreviewed/2024/10/GHSA-3x4w-v43m-f5m7/GHSA-3x4w-v43m-f5m7.json +++ b/advisories/unreviewed/2024/10/GHSA-3x4w-v43m-f5m7/GHSA-3x4w-v43m-f5m7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3x4w-v43m-f5m7", - "modified": "2024-10-11T18:32:49Z", + "modified": "2024-10-15T15:30:49Z", "published": "2024-10-11T18:32:49Z", "aliases": [ "CVE-2024-47489" diff --git a/advisories/unreviewed/2024/10/GHSA-47ww-vfc5-5gxw/GHSA-47ww-vfc5-5gxw.json b/advisories/unreviewed/2024/10/GHSA-47ww-vfc5-5gxw/GHSA-47ww-vfc5-5gxw.json index f183e91f584..1fa3586e7d5 100644 --- a/advisories/unreviewed/2024/10/GHSA-47ww-vfc5-5gxw/GHSA-47ww-vfc5-5gxw.json +++ b/advisories/unreviewed/2024/10/GHSA-47ww-vfc5-5gxw/GHSA-47ww-vfc5-5gxw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-47ww-vfc5-5gxw", - "modified": "2024-10-10T03:30:46Z", + "modified": "2024-10-15T15:30:45Z", "published": "2024-10-10T03:30:46Z", "aliases": [ "CVE-2024-9057" diff --git a/advisories/unreviewed/2024/10/GHSA-537j-q568-qwrw/GHSA-537j-q568-qwrw.json b/advisories/unreviewed/2024/10/GHSA-537j-q568-qwrw/GHSA-537j-q568-qwrw.json index 0e62159c81b..6be65d77adb 100644 --- a/advisories/unreviewed/2024/10/GHSA-537j-q568-qwrw/GHSA-537j-q568-qwrw.json +++ b/advisories/unreviewed/2024/10/GHSA-537j-q568-qwrw/GHSA-537j-q568-qwrw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-537j-q568-qwrw", - "modified": "2024-10-11T15:30:33Z", + "modified": "2024-10-15T15:30:48Z", "published": "2024-10-11T15:30:33Z", "aliases": [ "CVE-2024-8755" diff --git a/advisories/unreviewed/2024/10/GHSA-53m6-g2mp-6mj7/GHSA-53m6-g2mp-6mj7.json b/advisories/unreviewed/2024/10/GHSA-53m6-g2mp-6mj7/GHSA-53m6-g2mp-6mj7.json index 4afa3ba34aa..2f1e3f12e24 100644 --- a/advisories/unreviewed/2024/10/GHSA-53m6-g2mp-6mj7/GHSA-53m6-g2mp-6mj7.json +++ b/advisories/unreviewed/2024/10/GHSA-53m6-g2mp-6mj7/GHSA-53m6-g2mp-6mj7.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-201" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/10/GHSA-55qg-f678-jcg9/GHSA-55qg-f678-jcg9.json b/advisories/unreviewed/2024/10/GHSA-55qg-f678-jcg9/GHSA-55qg-f678-jcg9.json new file mode 100644 index 00000000000..f49f80cf053 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-55qg-f678-jcg9/GHSA-55qg-f678-jcg9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55qg-f678-jcg9", + "modified": "2024-10-15T15:30:54Z", + "published": "2024-10-15T15:30:54Z", + "aliases": [ + "CVE-2024-48278" + ], + "details": "Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48278" + }, + { + "type": "WEB", + "url": "https://github.com/m14r41/Writeups/blob/main/CVE/phpGurukul/User%20Registration%20%26%20Login%20and%20User%20Management%20System%20With%20admin%20panel/CSRF%20-%20Profile.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5645-gr78-qx8w/GHSA-5645-gr78-qx8w.json b/advisories/unreviewed/2024/10/GHSA-5645-gr78-qx8w/GHSA-5645-gr78-qx8w.json index 66b5676194e..e94a90d49cb 100644 --- a/advisories/unreviewed/2024/10/GHSA-5645-gr78-qx8w/GHSA-5645-gr78-qx8w.json +++ b/advisories/unreviewed/2024/10/GHSA-5645-gr78-qx8w/GHSA-5645-gr78-qx8w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5645-gr78-qx8w", - "modified": "2024-10-04T18:31:11Z", + "modified": "2024-10-15T15:30:45Z", "published": "2024-10-04T18:31:11Z", "aliases": [ "CVE-2024-38039" @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-80" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/10/GHSA-6jgw-rgmm-7cv6/GHSA-6jgw-rgmm-7cv6.json b/advisories/unreviewed/2024/10/GHSA-6jgw-rgmm-7cv6/GHSA-6jgw-rgmm-7cv6.json new file mode 100644 index 00000000000..cc41b214fb2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6jgw-rgmm-7cv6/GHSA-6jgw-rgmm-7cv6.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jgw-rgmm-7cv6", + "modified": "2024-10-15T15:30:56Z", + "published": "2024-10-15T15:30:56Z", + "aliases": [ + "CVE-2024-9979" + ], + "details": "A flaw was found in PyO3. This vulnerability causes a use-after-free issue, potentially leading to memory corruption or crashes via unsound borrowing from weak Python references.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9979" + }, + { + "type": "WEB", + "url": "https://github.com/PyO3/pyo3/pull/4590" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-9979" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2318646" + }, + { + "type": "WEB", + "url": "https://crates.io/crates/pyo3" + }, + { + "type": "WEB", + "url": "https://rustsec.org/advisories/RUSTSEC-2024-0378.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6rfh-8xcw-f6f2/GHSA-6rfh-8xcw-f6f2.json b/advisories/unreviewed/2024/10/GHSA-6rfh-8xcw-f6f2/GHSA-6rfh-8xcw-f6f2.json new file mode 100644 index 00000000000..18f7f670809 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6rfh-8xcw-f6f2/GHSA-6rfh-8xcw-f6f2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rfh-8xcw-f6f2", + "modified": "2024-10-15T15:30:55Z", + "published": "2024-10-15T15:30:55Z", + "aliases": [ + "CVE-2024-48282" + ], + "details": "A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the femail parameter in a POST HTTP request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48282" + }, + { + "type": "WEB", + "url": "https://github.com/m14r41/Writeups/blob/main/CVE/phpGurukul/User%20Registration%20%26%20Login%20and%20User%20Management%20System%20With%20admin%20panel/SQL%20Injection%20-%20Forget%20Password.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-75jw-84pf-jxc9/GHSA-75jw-84pf-jxc9.json b/advisories/unreviewed/2024/10/GHSA-75jw-84pf-jxc9/GHSA-75jw-84pf-jxc9.json new file mode 100644 index 00000000000..f20cf517ca9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-75jw-84pf-jxc9/GHSA-75jw-84pf-jxc9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75jw-84pf-jxc9", + "modified": "2024-10-15T15:30:54Z", + "published": "2024-10-15T15:30:54Z", + "aliases": [ + "CVE-2024-48280" + ], + "details": "A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL command via the fromdate parameter in a POST HTTP request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48280" + }, + { + "type": "WEB", + "url": "https://github.com/m14r41/Writeups/blob/main/CVE/phpGurukul/User%20Registration%20%26%20Login%20and%20User%20Management%20System%20With%20admin%20panel/SQL%20Injection%20-%20Bw%20Date%20Report%20%28%20fromdate%29.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-79v4-xhfm-cr97/GHSA-79v4-xhfm-cr97.json b/advisories/unreviewed/2024/10/GHSA-79v4-xhfm-cr97/GHSA-79v4-xhfm-cr97.json index 2caf07d1893..8157e4b450b 100644 --- a/advisories/unreviewed/2024/10/GHSA-79v4-xhfm-cr97/GHSA-79v4-xhfm-cr97.json +++ b/advisories/unreviewed/2024/10/GHSA-79v4-xhfm-cr97/GHSA-79v4-xhfm-cr97.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-79v4-xhfm-cr97", - "modified": "2024-10-11T18:32:49Z", + "modified": "2024-10-15T15:30:49Z", "published": "2024-10-11T18:32:49Z", "aliases": [ "CVE-2024-47491" diff --git a/advisories/unreviewed/2024/10/GHSA-994f-pcw4-m52m/GHSA-994f-pcw4-m52m.json b/advisories/unreviewed/2024/10/GHSA-994f-pcw4-m52m/GHSA-994f-pcw4-m52m.json new file mode 100644 index 00000000000..51f17e69177 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-994f-pcw4-m52m/GHSA-994f-pcw4-m52m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-994f-pcw4-m52m", + "modified": "2024-10-15T15:30:55Z", + "published": "2024-10-15T15:30:55Z", + "aliases": [ + "CVE-2024-48283" + ], + "details": "Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-result.php via the searchkey parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48283" + }, + { + "type": "WEB", + "url": "https://github.com/m14r41/Writeups/blob/main/CVE/phpGurukul/User%20Registration%20%26%20Login%20and%20User%20Management%20System%20With%20admin%20panel/SQL%20Injection%20-%20Search.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9f2c-45xq-c486/GHSA-9f2c-45xq-c486.json b/advisories/unreviewed/2024/10/GHSA-9f2c-45xq-c486/GHSA-9f2c-45xq-c486.json index 62db6e22657..df21666195d 100644 --- a/advisories/unreviewed/2024/10/GHSA-9f2c-45xq-c486/GHSA-9f2c-45xq-c486.json +++ b/advisories/unreviewed/2024/10/GHSA-9f2c-45xq-c486/GHSA-9f2c-45xq-c486.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9f2c-45xq-c486", - "modified": "2024-10-09T18:31:43Z", + "modified": "2024-10-15T15:30:45Z", "published": "2024-10-09T18:31:43Z", "aliases": [ "CVE-2024-9465" ], "details": "An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red" diff --git a/advisories/unreviewed/2024/10/GHSA-cpxc-2w9f-g929/GHSA-cpxc-2w9f-g929.json b/advisories/unreviewed/2024/10/GHSA-cpxc-2w9f-g929/GHSA-cpxc-2w9f-g929.json index 02f6a807708..e4a0697a02b 100644 --- a/advisories/unreviewed/2024/10/GHSA-cpxc-2w9f-g929/GHSA-cpxc-2w9f-g929.json +++ b/advisories/unreviewed/2024/10/GHSA-cpxc-2w9f-g929/GHSA-cpxc-2w9f-g929.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-116", "CWE-20" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/10/GHSA-fc9h-whq2-v747/GHSA-fc9h-whq2-v747.json b/advisories/unreviewed/2024/10/GHSA-fc9h-whq2-v747/GHSA-fc9h-whq2-v747.json new file mode 100644 index 00000000000..b4e0ac04731 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fc9h-whq2-v747/GHSA-fc9h-whq2-v747.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc9h-whq2-v747", + "modified": "2024-10-15T15:30:56Z", + "published": "2024-10-15T15:30:56Z", + "aliases": [ + "CVE-2024-48948" + ], + "details": "The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the elliptic curve's base point is smaller than the hash, because of an _truncateToN anomaly. This leads to valid signatures being rejected. Legitimate transactions or communications may be incorrectly flagged as invalid.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48948" + }, + { + "type": "WEB", + "url": "https://github.com/indutny/elliptic/issues/321" + }, + { + "type": "WEB", + "url": "https://github.com/indutny/elliptic/pull/322" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fpxg-3hxf-5mvr/GHSA-fpxg-3hxf-5mvr.json b/advisories/unreviewed/2024/10/GHSA-fpxg-3hxf-5mvr/GHSA-fpxg-3hxf-5mvr.json index 322078139b2..9d991af8983 100644 --- a/advisories/unreviewed/2024/10/GHSA-fpxg-3hxf-5mvr/GHSA-fpxg-3hxf-5mvr.json +++ b/advisories/unreviewed/2024/10/GHSA-fpxg-3hxf-5mvr/GHSA-fpxg-3hxf-5mvr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fpxg-3hxf-5mvr", - "modified": "2024-10-11T18:32:49Z", + "modified": "2024-10-15T15:30:49Z", "published": "2024-10-11T18:32:49Z", "aliases": [ "CVE-2024-47493" diff --git a/advisories/unreviewed/2024/10/GHSA-gc35-q76c-xj63/GHSA-gc35-q76c-xj63.json b/advisories/unreviewed/2024/10/GHSA-gc35-q76c-xj63/GHSA-gc35-q76c-xj63.json index cb9510d6000..f882f67ad60 100644 --- a/advisories/unreviewed/2024/10/GHSA-gc35-q76c-xj63/GHSA-gc35-q76c-xj63.json +++ b/advisories/unreviewed/2024/10/GHSA-gc35-q76c-xj63/GHSA-gc35-q76c-xj63.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gc35-q76c-xj63", - "modified": "2024-10-09T15:32:21Z", + "modified": "2024-10-15T15:30:45Z", "published": "2024-10-09T15:32:21Z", "aliases": [ "CVE-2024-7293" diff --git a/advisories/unreviewed/2024/10/GHSA-gjm5-824v-4vq3/GHSA-gjm5-824v-4vq3.json b/advisories/unreviewed/2024/10/GHSA-gjm5-824v-4vq3/GHSA-gjm5-824v-4vq3.json index 4c2b46fc703..0dff56632b0 100644 --- a/advisories/unreviewed/2024/10/GHSA-gjm5-824v-4vq3/GHSA-gjm5-824v-4vq3.json +++ b/advisories/unreviewed/2024/10/GHSA-gjm5-824v-4vq3/GHSA-gjm5-824v-4vq3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gjm5-824v-4vq3", - "modified": "2024-10-04T18:31:10Z", + "modified": "2024-10-15T15:30:45Z", "published": "2024-10-04T18:31:10Z", "aliases": [ "CVE-2024-38036" diff --git a/advisories/unreviewed/2024/10/GHSA-h2fm-p5xw-r67q/GHSA-h2fm-p5xw-r67q.json b/advisories/unreviewed/2024/10/GHSA-h2fm-p5xw-r67q/GHSA-h2fm-p5xw-r67q.json index 4e2cc03e14a..74dd248eab7 100644 --- a/advisories/unreviewed/2024/10/GHSA-h2fm-p5xw-r67q/GHSA-h2fm-p5xw-r67q.json +++ b/advisories/unreviewed/2024/10/GHSA-h2fm-p5xw-r67q/GHSA-h2fm-p5xw-r67q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h2fm-p5xw-r67q", - "modified": "2024-10-09T15:32:21Z", + "modified": "2024-10-15T15:30:45Z", "published": "2024-10-09T15:32:21Z", "aliases": [ "CVE-2024-7292" diff --git a/advisories/unreviewed/2024/10/GHSA-h8v4-hc3c-vf8p/GHSA-h8v4-hc3c-vf8p.json b/advisories/unreviewed/2024/10/GHSA-h8v4-hc3c-vf8p/GHSA-h8v4-hc3c-vf8p.json index 02ec4123a3a..f3ddd18383f 100644 --- a/advisories/unreviewed/2024/10/GHSA-h8v4-hc3c-vf8p/GHSA-h8v4-hc3c-vf8p.json +++ b/advisories/unreviewed/2024/10/GHSA-h8v4-hc3c-vf8p/GHSA-h8v4-hc3c-vf8p.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h8v4-hc3c-vf8p", - "modified": "2024-10-09T18:31:43Z", + "modified": "2024-10-15T15:30:45Z", "published": "2024-10-09T18:31:43Z", "aliases": [ "CVE-2024-9467" ], "details": "A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that user clicks on a malicious link, allowing phishing attacks that could lead to Expedition browser session theft.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red" diff --git a/advisories/unreviewed/2024/10/GHSA-m36f-v9qc-f9h5/GHSA-m36f-v9qc-f9h5.json b/advisories/unreviewed/2024/10/GHSA-m36f-v9qc-f9h5/GHSA-m36f-v9qc-f9h5.json index 954e681e6fa..7b01eaf0419 100644 --- a/advisories/unreviewed/2024/10/GHSA-m36f-v9qc-f9h5/GHSA-m36f-v9qc-f9h5.json +++ b/advisories/unreviewed/2024/10/GHSA-m36f-v9qc-f9h5/GHSA-m36f-v9qc-f9h5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m36f-v9qc-f9h5", - "modified": "2024-10-15T09:30:32Z", + "modified": "2024-10-15T15:30:53Z", "published": "2024-10-15T09:30:31Z", "aliases": [ "CVE-2024-47944" ], "details": "The device directly executes .patch firmware upgrade files on a USB stick without any prior authentication in the admin interface. This leads to an unauthenticated code execution via the firmware upgrade function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-1299" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T09:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-pcmx-c2wg-899q/GHSA-pcmx-c2wg-899q.json b/advisories/unreviewed/2024/10/GHSA-pcmx-c2wg-899q/GHSA-pcmx-c2wg-899q.json index f9d22ff2cd3..5a9af040a8e 100644 --- a/advisories/unreviewed/2024/10/GHSA-pcmx-c2wg-899q/GHSA-pcmx-c2wg-899q.json +++ b/advisories/unreviewed/2024/10/GHSA-pcmx-c2wg-899q/GHSA-pcmx-c2wg-899q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pcmx-c2wg-899q", - "modified": "2024-10-09T15:32:21Z", + "modified": "2024-10-15T15:30:45Z", "published": "2024-10-09T15:32:21Z", "aliases": [ "CVE-2024-7294" diff --git a/advisories/unreviewed/2024/10/GHSA-pggm-8jq8-xmxw/GHSA-pggm-8jq8-xmxw.json b/advisories/unreviewed/2024/10/GHSA-pggm-8jq8-xmxw/GHSA-pggm-8jq8-xmxw.json new file mode 100644 index 00000000000..391f269364d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pggm-8jq8-xmxw/GHSA-pggm-8jq8-xmxw.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pggm-8jq8-xmxw", + "modified": "2024-10-15T15:30:56Z", + "published": "2024-10-15T15:30:56Z", + "aliases": [ + "CVE-2024-9977" + ], + "details": "A vulnerability, which was classified as critical, was found in MitraStar GPT-2541GNAC BR_g5.6_1.11(WVK.0)b26. Affected is an unknown function of the file /cgi-bin/settings-firewall.cgi of the component Firewall Settings Page. The manipulation of the argument SrcInterface leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. We tried to contact the vendor early about the disclosure but the official mail address was not working properly.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9977" + }, + { + "type": "WEB", + "url": "https://github.com/peritocibernetico/VivoCodeExecutionFirewall" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.280344" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.280344" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.423561" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qh35-4qrq-2527/GHSA-qh35-4qrq-2527.json b/advisories/unreviewed/2024/10/GHSA-qh35-4qrq-2527/GHSA-qh35-4qrq-2527.json index 5ce3d6b15a9..44f8d88c018 100644 --- a/advisories/unreviewed/2024/10/GHSA-qh35-4qrq-2527/GHSA-qh35-4qrq-2527.json +++ b/advisories/unreviewed/2024/10/GHSA-qh35-4qrq-2527/GHSA-qh35-4qrq-2527.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-r2fh-mj7f-v33r/GHSA-r2fh-mj7f-v33r.json b/advisories/unreviewed/2024/10/GHSA-r2fh-mj7f-v33r/GHSA-r2fh-mj7f-v33r.json index 37118633c93..114571295a0 100644 --- a/advisories/unreviewed/2024/10/GHSA-r2fh-mj7f-v33r/GHSA-r2fh-mj7f-v33r.json +++ b/advisories/unreviewed/2024/10/GHSA-r2fh-mj7f-v33r/GHSA-r2fh-mj7f-v33r.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r2fh-mj7f-v33r", - "modified": "2024-10-09T18:31:43Z", + "modified": "2024-10-15T15:30:45Z", "published": "2024-10-09T18:31:43Z", "aliases": [ "CVE-2024-9463" ], "details": "An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red" diff --git a/advisories/unreviewed/2024/10/GHSA-r7wf-fpff-w68q/GHSA-r7wf-fpff-w68q.json b/advisories/unreviewed/2024/10/GHSA-r7wf-fpff-w68q/GHSA-r7wf-fpff-w68q.json index 4226bc11030..1b46f1df21b 100644 --- a/advisories/unreviewed/2024/10/GHSA-r7wf-fpff-w68q/GHSA-r7wf-fpff-w68q.json +++ b/advisories/unreviewed/2024/10/GHSA-r7wf-fpff-w68q/GHSA-r7wf-fpff-w68q.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r7wf-fpff-w68q", - "modified": "2024-10-09T18:31:43Z", + "modified": "2024-10-15T15:30:45Z", "published": "2024-10-09T18:31:43Z", "aliases": [ "CVE-2024-9464" ], "details": "An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Red" diff --git a/advisories/unreviewed/2024/10/GHSA-v4pc-7q3f-7vf2/GHSA-v4pc-7q3f-7vf2.json b/advisories/unreviewed/2024/10/GHSA-v4pc-7q3f-7vf2/GHSA-v4pc-7q3f-7vf2.json index 3cd1082c442..cf76726324e 100644 --- a/advisories/unreviewed/2024/10/GHSA-v4pc-7q3f-7vf2/GHSA-v4pc-7q3f-7vf2.json +++ b/advisories/unreviewed/2024/10/GHSA-v4pc-7q3f-7vf2/GHSA-v4pc-7q3f-7vf2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v4pc-7q3f-7vf2", - "modified": "2024-10-10T03:30:45Z", + "modified": "2024-10-15T15:30:45Z", "published": "2024-10-10T03:30:45Z", "aliases": [ "CVE-2024-8513" diff --git a/advisories/unreviewed/2024/10/GHSA-vgrm-w974-j729/GHSA-vgrm-w974-j729.json b/advisories/unreviewed/2024/10/GHSA-vgrm-w974-j729/GHSA-vgrm-w974-j729.json new file mode 100644 index 00000000000..f4248225ce8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vgrm-w974-j729/GHSA-vgrm-w974-j729.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgrm-w974-j729", + "modified": "2024-10-15T15:30:54Z", + "published": "2024-10-15T15:30:54Z", + "aliases": [ + "CVE-2024-48279" + ], + "details": "A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary HTML code via the searchkey parameter in a POST HTTP request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48279" + }, + { + "type": "WEB", + "url": "https://github.com/m14r41/Writeups/blob/main/CVE/phpGurukul/User%20Registration%20%26%20Login%20and%20User%20Management%20System%20With%20admin%20panel/HTML%20Injection%20-%20Search.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w25r-358w-353h/GHSA-w25r-358w-353h.json b/advisories/unreviewed/2024/10/GHSA-w25r-358w-353h/GHSA-w25r-358w-353h.json index ed52eb0ac7f..c790360af0e 100644 --- a/advisories/unreviewed/2024/10/GHSA-w25r-358w-353h/GHSA-w25r-358w-353h.json +++ b/advisories/unreviewed/2024/10/GHSA-w25r-358w-353h/GHSA-w25r-358w-353h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w25r-358w-353h", - "modified": "2024-10-10T03:30:46Z", + "modified": "2024-10-15T15:30:45Z", "published": "2024-10-10T03:30:46Z", "aliases": [ "CVE-2024-9072" diff --git a/advisories/unreviewed/2024/10/GHSA-wqr7-r7h2-v2j2/GHSA-wqr7-r7h2-v2j2.json b/advisories/unreviewed/2024/10/GHSA-wqr7-r7h2-v2j2/GHSA-wqr7-r7h2-v2j2.json new file mode 100644 index 00000000000..ceeae582164 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wqr7-r7h2-v2j2/GHSA-wqr7-r7h2-v2j2.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqr7-r7h2-v2j2", + "modified": "2024-10-15T15:30:56Z", + "published": "2024-10-15T15:30:56Z", + "aliases": [ + "CVE-2024-9986" + ], + "details": "A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file member_register.php. The manipulation of the argument fullname/username/password/email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter \"password\" to be affected. But it must be assumed that other parameters are affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9986" + }, + { + "type": "WEB", + "url": "https://github.com/Lanxiy7th/lx_CVE_report-/issues/16" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.280349" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.280349" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.423887" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-15T13:15:11Z" + } +} \ No newline at end of file