diff --git a/advisories/unreviewed/2024/12/GHSA-32wh-2cq7-f29f/GHSA-32wh-2cq7-f29f.json b/advisories/unreviewed/2024/12/GHSA-32wh-2cq7-f29f/GHSA-32wh-2cq7-f29f.json new file mode 100644 index 00000000000..bb105a61276 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-32wh-2cq7-f29f/GHSA-32wh-2cq7-f29f.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32wh-2cq7-f29f", + "modified": "2024-12-26T09:30:46Z", + "published": "2024-12-26T09:30:46Z", + "aliases": [ + "CVE-2024-12941" + ], + "details": "A vulnerability was found in CodeAstro Blood Donor Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /pages/deletedannounce.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12941" + }, + { + "type": "WEB", + "url": "https://github.com/Bea1ee/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://codeastro.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289301" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289301" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.468317" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-26T08:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-3rrr-6hj5-967g/GHSA-3rrr-6hj5-967g.json b/advisories/unreviewed/2024/12/GHSA-3rrr-6hj5-967g/GHSA-3rrr-6hj5-967g.json new file mode 100644 index 00000000000..0a007df7a5f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-3rrr-6hj5-967g/GHSA-3rrr-6hj5-967g.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rrr-6hj5-967g", + "modified": "2024-12-26T09:30:46Z", + "published": "2024-12-26T09:30:46Z", + "aliases": [ + "CVE-2024-12943" + ], + "details": "A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ownersignup.php. The manipulation of the argument f/e/p/m/o/n/c/s/ci/a leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter \"m\" to be affected. But it must be assumed that many other parameters are affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12943" + }, + { + "type": "WEB", + "url": "https://github.com/Wind-liberty/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://codeastro.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289303" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289303" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.468375" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-26T09:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-4c4x-854c-52cx/GHSA-4c4x-854c-52cx.json b/advisories/unreviewed/2024/12/GHSA-4c4x-854c-52cx/GHSA-4c4x-854c-52cx.json new file mode 100644 index 00000000000..99ccf38daa9 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4c4x-854c-52cx/GHSA-4c4x-854c-52cx.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4c4x-854c-52cx", + "modified": "2024-12-26T09:30:46Z", + "published": "2024-12-26T09:30:46Z", + "aliases": [ + "CVE-2024-12944" + ], + "details": "A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /signin.php. The manipulation of the argument u/p leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12944" + }, + { + "type": "WEB", + "url": "https://github.com/Wind-liberty/CVE/issues/2" + }, + { + "type": "WEB", + "url": "https://codeastro.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289304" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289304" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.468376" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-26T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7683-vm2j-m4cc/GHSA-7683-vm2j-m4cc.json b/advisories/unreviewed/2024/12/GHSA-7683-vm2j-m4cc/GHSA-7683-vm2j-m4cc.json new file mode 100644 index 00000000000..1abfc4d8f16 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7683-vm2j-m4cc/GHSA-7683-vm2j-m4cc.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7683-vm2j-m4cc", + "modified": "2024-12-26T09:30:46Z", + "published": "2024-12-26T09:30:46Z", + "aliases": [ + "CVE-2024-56433" + ], + "details": "shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56433" + }, + { + "type": "WEB", + "url": "https://github.com/shadow-maint/shadow/issues/1157" + }, + { + "type": "WEB", + "url": "https://github.com/shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs#L238-L241" + }, + { + "type": "WEB", + "url": "https://github.com/shadow-maint/shadow/releases/tag/4.4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1188" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-26T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7gwq-xm24-vx8r/GHSA-7gwq-xm24-vx8r.json b/advisories/unreviewed/2024/12/GHSA-7gwq-xm24-vx8r/GHSA-7gwq-xm24-vx8r.json new file mode 100644 index 00000000000..44f9ce787f2 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7gwq-xm24-vx8r/GHSA-7gwq-xm24-vx8r.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gwq-xm24-vx8r", + "modified": "2024-12-26T09:30:46Z", + "published": "2024-12-26T09:30:46Z", + "aliases": [ + "CVE-2024-12942" + ], + "details": "A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/admin_login.php. The manipulation of the argument username/password leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12942" + }, + { + "type": "WEB", + "url": "https://1000projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/dawatermelon/CVE/blob/main/Portfolio%20Management%20System%20MCA%20Project/README.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289302" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289302" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.468329" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-26T08:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-7p62-2367-437g/GHSA-7p62-2367-437g.json b/advisories/unreviewed/2024/12/GHSA-7p62-2367-437g/GHSA-7p62-2367-437g.json new file mode 100644 index 00000000000..409d5e2e128 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-7p62-2367-437g/GHSA-7p62-2367-437g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p62-2367-437g", + "modified": "2024-12-26T09:30:46Z", + "published": "2024-12-26T09:30:46Z", + "aliases": [ + "CVE-2023-7300" + ], + "details": "Huawei Home Music System has a path traversal vulnerability. Successful exploitation of this vulnerability may cause the music host file to be deleted or the file permission to be changed.(Vulnerability ID:HWPSIRT-2023-60613)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7300" + }, + { + "type": "WEB", + "url": "https://www.huawei.com/en/psirt/security-advisories/2024/huawei-sa-ptvihhms-91f7c6fa-en" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-26T09:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-fm5q-8q9h-232m/GHSA-fm5q-8q9h-232m.json b/advisories/unreviewed/2024/12/GHSA-fm5q-8q9h-232m/GHSA-fm5q-8q9h-232m.json new file mode 100644 index 00000000000..904614f7b7c --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-fm5q-8q9h-232m/GHSA-fm5q-8q9h-232m.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm5q-8q9h-232m", + "modified": "2024-12-26T09:30:46Z", + "published": "2024-12-26T09:30:46Z", + "aliases": [ + "CVE-2024-12939" + ], + "details": "A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as critical. This issue affects the function add_edu of the file /_parse/_all_edits.php. The manipulation of the argument degree leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12939" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/Hl0kk/cve/blob/main/sql-hi.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289295" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289295" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.467816" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-26T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-x2wp-f5ch-jc9v/GHSA-x2wp-f5ch-jc9v.json b/advisories/unreviewed/2024/12/GHSA-x2wp-f5ch-jc9v/GHSA-x2wp-f5ch-jc9v.json new file mode 100644 index 00000000000..3fc6701a8f3 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x2wp-f5ch-jc9v/GHSA-x2wp-f5ch-jc9v.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2wp-f5ch-jc9v", + "modified": "2024-12-26T09:30:46Z", + "published": "2024-12-26T09:30:46Z", + "aliases": [ + "CVE-2024-12940" + ], + "details": "A vulnerability has been found in 1000 Projects Attendance Tracking Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/student_action.php. The manipulation of the argument student_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12940" + }, + { + "type": "WEB", + "url": "https://github.com/bug3536/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://1000projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.289300" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.289300" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.468286" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-26T07:15:11Z" + } +} \ No newline at end of file