From ddaaf75ec8f8846263870cf0cff1ece87f03c3b0 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 7 Jul 2023 19:02:36 +0000 Subject: [PATCH] Publish Advisories GHSA-25q6-m425-9fqr GHSA-4r4f-jrvw-h727 --- .../2022/07/GHSA-25q6-m425-9fqr/GHSA-25q6-m425-9fqr.json | 4 ++-- .../2022/09/GHSA-4r4f-jrvw-h727/GHSA-4r4f-jrvw-h727.json | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/advisories/github-reviewed/2022/07/GHSA-25q6-m425-9fqr/GHSA-25q6-m425-9fqr.json b/advisories/github-reviewed/2022/07/GHSA-25q6-m425-9fqr/GHSA-25q6-m425-9fqr.json index 390f2199565..a9ef8629ab4 100644 --- a/advisories/github-reviewed/2022/07/GHSA-25q6-m425-9fqr/GHSA-25q6-m425-9fqr.json +++ b/advisories/github-reviewed/2022/07/GHSA-25q6-m425-9fqr/GHSA-25q6-m425-9fqr.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-25q6-m425-9fqr", - "modified": "2022-08-06T09:24:41Z", + "modified": "2023-07-07T19:02:06Z", "published": "2022-07-29T00:00:47Z", "aliases": [ "CVE-2022-34140" ], "summary": "Feehi CMS Cross-site Scripting", - "details": "A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username field.", + "details": "A stored cross-site scripting (XSS) vulnerability in `/index.php?r=site%2Fsignup` of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username field.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2022/09/GHSA-4r4f-jrvw-h727/GHSA-4r4f-jrvw-h727.json b/advisories/github-reviewed/2022/09/GHSA-4r4f-jrvw-h727/GHSA-4r4f-jrvw-h727.json index bbc41f525cd..fb8d5e2e203 100644 --- a/advisories/github-reviewed/2022/09/GHSA-4r4f-jrvw-h727/GHSA-4r4f-jrvw-h727.json +++ b/advisories/github-reviewed/2022/09/GHSA-4r4f-jrvw-h727/GHSA-4r4f-jrvw-h727.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-4r4f-jrvw-h727", - "modified": "2022-09-19T20:18:43Z", + "modified": "2023-07-07T19:01:25Z", "published": "2022-09-15T00:00:19Z", "aliases": [ "CVE-2022-38796" ], - "summary": "Feehi CMS host header injection vulnerability may allow attacker to spoof a particular header", + "summary": "Feehi CMS host header injection vulnerability", "details": "A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by abusing password reset emails.", "severity": [ {