Publish Advisories

GHSA-5vvj-g783-6xf4
GHSA-4pj4-pm6x-xf9x
GHSA-5vq6-44f5-4pc9
GHSA-7gjf-ch6v-37rf
GHSA-9f8f-453p-rg87
GHSA-fwjp-fr8h-pc84
GHSA-g8r2-4q75-c55g
GHSA-gp6m-m3pw-7m24
GHSA-m848-8f5r-6j4g
GHSA-p59q-w6ff-wf6f
GHSA-r5mh-qgc2-26p2
GHSA-r6mp-q3jr-f6gv
GHSA-rpvg-h6p6-42qj
GHSA-vmvr-82pf-3p87
GHSA-xm4w-v978-7gcx
This commit is contained in:
advisory-database[bot]
2024-06-25 00:36:13 +00:00
parent 6e0f992c48
commit dcdbbf352d
15 changed files with 511 additions and 1 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5vvj-g783-6xf4",
"modified": "2024-03-13T21:31:03Z",
"modified": "2024-06-25T00:34:45Z",
"published": "2024-03-13T21:31:02Z",
"aliases": [
"CVE-2024-22167"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://www.westerndigital.com/support/product-security/wdc-24002-sandisk-privateaccess-desktop-app-v-6-4-10"
},
{
"type": "WEB",
"url": "https://www.westerndigital.com/support/product-security/wdc-24002-sandisk-privateaccess-desktop-app-v-6-4-11"
}
],
"database_specific": {
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4pj4-pm6x-xf9x",
"modified": "2024-06-25T00:34:46Z",
"published": "2024-06-25T00:34:46Z",
"aliases": [
"CVE-2023-50029"
],
"details": "PHP Injection vulnerability in the module \"M4 PDF Extensions\" (m4pdf) up to version 3.3.2 from PrestaAddons for PrestaShop allows attackers to run arbitrary code via the M4PDF::saveTemplate() method.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50029"
},
{
"type": "WEB",
"url": "https://security.friendsofpresta.org/modules/2024/06/20/m4pdf.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T23:15:10Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5vq6-44f5-4pc9",
"modified": "2024-06-25T00:34:46Z",
"published": "2024-06-25T00:34:46Z",
"aliases": [
"CVE-2024-34991"
],
"details": "In the module \"Axepta\" (axepta) before 1.3.4 from Quadra Informatique for PrestaShop, a guest can download partial credit card information (expiry date) / postal address / email / etc. without restriction due to a lack of permissions control.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34991"
},
{
"type": "WEB",
"url": "https://security.friendsofpresta.org/modules/2024/06/20/axepta.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T22:15:10Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7gjf-ch6v-37rf",
"modified": "2024-06-25T00:34:45Z",
"published": "2024-06-25T00:34:45Z",
"aliases": [
"CVE-2024-33898"
],
"details": "Axiros AXESS Auto Configuration Server (ACS) 4.x and 5.0.0 has Incorrect Access Control. An authorization bypass allows remote attackers to achieve unauthenticated remote code execution.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33898"
},
{
"type": "WEB",
"url": "https://www.axiros.com/2024/03/vulnerability-in-axusermanager"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T22:15:10Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9f8f-453p-rg87",
"modified": "2024-06-25T00:34:46Z",
"published": "2024-06-25T00:34:46Z",
"aliases": [
"CVE-2024-6293"
],
"details": "Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6293"
},
{
"type": "WEB",
"url": "https://chromereleases.googleblog.com/2024/06/stable-channel-update-for-desktop_24.html"
},
{
"type": "WEB",
"url": "https://issues.chromium.org/issues/345993680"
}
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T22:15:10Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fwjp-fr8h-pc84",
"modified": "2024-06-25T00:34:47Z",
"published": "2024-06-25T00:34:47Z",
"aliases": [
"CVE-2024-36681"
],
"details": "SQL Injection vulnerability in the module \"Isotope\" (pk_isotope) <=1.7.3 from Promokit.eu for PrestaShop allows attackers to obtain sensitive information and cause other impacts via `pk_isotope::saveData` and `pk_isotope::removeData` methods.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36681"
},
{
"type": "WEB",
"url": "https://security.friendsofpresta.org/modules/2024/06/20/pk_isotope.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T23:15:10Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g8r2-4q75-c55g",
"modified": "2024-06-25T00:34:46Z",
"published": "2024-06-25T00:34:46Z",
"aliases": [
"CVE-2024-22168"
],
"details": "A Cross-Site Scripting (XSS) vulnerability on the My Cloud, My Cloud Home, SanDisk ibi, and WD Cloud web apps was found which could allow an attacker to redirect the user to a crafted domain and reset their credentials, or to execute arbitrary client-side code in the users browser session to carry out malicious activities.The web apps for these devices have been automatically updated to resolve this vulnerability and improve the security of your devices and data.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22168"
},
{
"type": "WEB",
"url": "https://www.westerndigital.com/support/product-security/wdc-24003-western-digital-my-cloud-os-5-my-cloud-home-sandisk-ibi-and-wd-cloud-web-app-update"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T23:15:10Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gp6m-m3pw-7m24",
"modified": "2024-06-25T00:34:47Z",
"published": "2024-06-25T00:34:47Z",
"aliases": [
"CVE-2024-34992"
],
"details": "SQL Injection vulnerability in the module \"Help Desk - Customer Support Management System\" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop allows attackers to obtain sensitive information and cause other impacts via 'Tickets::getsearchedtickets()'",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34992"
},
{
"type": "WEB",
"url": "https://security.friendsofpresta.org/modules/2024/06/20/helpdesk.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T23:15:10Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m848-8f5r-6j4g",
"modified": "2024-06-25T00:34:46Z",
"published": "2024-06-25T00:34:46Z",
"aliases": [
"CVE-2024-6292"
],
"details": "Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6292"
},
{
"type": "WEB",
"url": "https://chromereleases.googleblog.com/2024/06/stable-channel-update-for-desktop_24.html"
},
{
"type": "WEB",
"url": "https://issues.chromium.org/issues/342545100"
}
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T22:15:10Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p59q-w6ff-wf6f",
"modified": "2024-06-25T00:34:45Z",
"published": "2024-06-25T00:34:45Z",
"aliases": [
"CVE-2023-45195"
],
"details": "Adminer and AdminerEvo are vulnerable to SSRF via database connection fields. This could allow an unauthenticated remote attacker to enumerate or access systems the attacker would not otherwise have access to. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.4.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45195"
},
{
"type": "WEB",
"url": "https://github.com/adminerevo/adminerevo/pull/102/commits/18f3167bbcbec3bc746f62db72e016aa99144efc"
}
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T22:15:10Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r5mh-qgc2-26p2",
"modified": "2024-06-25T00:34:46Z",
"published": "2024-06-25T00:34:46Z",
"aliases": [
"CVE-2024-6290"
],
"details": "Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6290"
},
{
"type": "WEB",
"url": "https://chromereleases.googleblog.com/2024/06/stable-channel-update-for-desktop_24.html"
},
{
"type": "WEB",
"url": "https://issues.chromium.org/issues/342428008"
}
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T22:15:10Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r6mp-q3jr-f6gv",
"modified": "2024-06-25T00:34:46Z",
"published": "2024-06-25T00:34:46Z",
"aliases": [
"CVE-2024-34988"
],
"details": "SQL injection vulnerability in the module \"Complete for Create a Quote in Frontend + Backend Pro\" (askforaquotemodul) <= 1.0.51 from Buy Addons for PrestaShop allows attackers to view sensitive information and cause other impacts via methods `AskforaquotemodulcustomernewquoteModuleFrontController::run()`, `AskforaquotemoduladdproductnewquoteModuleFrontController::run()`, `AskforaquotemodulCouponcodeModuleFrontController::run()`, `AskforaquotemodulgetshippingcostModuleFrontController::run()`, `AskforaquotemodulgetstateModuleFrontController::run().`",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34988"
},
{
"type": "WEB",
"url": "https://security.friendsofpresta.org/modules/2024/06/20/askforaquotemodul.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T23:15:10Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rpvg-h6p6-42qj",
"modified": "2024-06-25T00:34:46Z",
"published": "2024-06-25T00:34:46Z",
"aliases": [
"CVE-2024-6291"
],
"details": "Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6291"
},
{
"type": "WEB",
"url": "https://chromereleases.googleblog.com/2024/06/stable-channel-update-for-desktop_24.html"
},
{
"type": "WEB",
"url": "https://issues.chromium.org/issues/40942995"
}
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T22:15:10Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vmvr-82pf-3p87",
"modified": "2024-06-25T00:34:47Z",
"published": "2024-06-25T00:34:47Z",
"aliases": [
"CVE-2024-36683"
],
"details": "SQL injection vulnerability in the module \"Products Alert\" (productsalert) before 1.7.4 from Smart Modules for PrestaShop allows attackers to obtain sensitive information and cause other impacts via the ProductsAlertAjaxProcessModuleFrontController::initContent method.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36683"
},
{
"type": "WEB",
"url": "https://security.friendsofpresta.org/modules/2024/06/20/productsalert.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T23:15:10Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xm4w-v978-7gcx",
"modified": "2024-06-25T00:34:46Z",
"published": "2024-06-25T00:34:46Z",
"aliases": [
"CVE-2024-36682"
],
"details": "In the module \"Theme settings\" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can download all email collected while SHOP is in maintenance mode. Due to a lack of permissions control, a guest can access the txt file which collect email when maintenance is enable which can lead to leak of personal information.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36682"
},
{
"type": "WEB",
"url": "https://security.friendsofpresta.org/modules/2024/06/20/pk_themesettings.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-24T22:15:10Z"
}
}