Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-02-05 18:32:59 +00:00
parent 36a3342001
commit e18db03b34
34 changed files with 725 additions and 44 deletions
@@ -36,7 +36,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-311"
"CWE-311",
"CWE-614"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://wpscan.com/vulnerability/fd50f2d6-e420-4220-b485-73f33227e8f8"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/176983/WordPress-Simple-URLs-Cross-Site-Scripting.html"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f47p-g3vj-j588",
"modified": "2023-06-23T21:30:33Z",
"modified": "2024-02-05T18:31:35Z",
"published": "2023-06-23T21:30:33Z",
"aliases": [
"CVE-2023-35759"
],
"details": "In Progress WhatsUp Gold before 23.0.0, an SNMP-related application endpoint failed to adequately sanitize malicious input. This could allow an unauthenticated attacker to execute arbitrary code in a victim's browser, aka XSS.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -21,13 +24,17 @@
{
"type": "WEB",
"url": "https://community.progress.com/s/article/Product-Alert-Bulletin-June-2023"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/176978/WhatsUp-Gold-2022-22.1.0-Build-39-Cross-Site-Scripting.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-06-23T20:15:09Z"
@@ -32,6 +32,10 @@
{
"type": "WEB",
"url": "https://zigrin.com/advisories/misp-stored-xss/"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/176975/MISP-2.4.171-Cross-Site-Scripting.html"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3r5f-38cp-r8x3",
"modified": "2023-10-11T18:30:27Z",
"modified": "2024-02-05T18:31:36Z",
"published": "2023-10-04T12:30:14Z",
"aliases": [
"CVE-2023-43261"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://github.com/win3zz/CVE-2023-43261"
},
{
"type": "WEB",
"url": "https://medium.com/%40win3zz/inside-the-router-how-i-accessed-industrial-routers-and-reported-the-flaws-29c34213dfdf"
},
{
"type": "WEB",
"url": "https://medium.com/@win3zz/inside-the-router-how-i-accessed-industrial-routers-and-reported-the-flaws-29c34213dfdf"
@@ -37,6 +41,10 @@
"type": "WEB",
"url": "http://milesight.com"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/176988/Milesight-UR5X-UR32L-UR32-UR35-UR41-Credential-Leakage.html"
},
{
"type": "WEB",
"url": "http://ur5x.com"
@@ -46,7 +54,7 @@
"cwe_ids": [
"CWE-532"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-04T12:15:10Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j6jf-4ffc-g9xf",
"modified": "2023-10-31T15:30:20Z",
"modified": "2024-02-05T18:31:36Z",
"published": "2023-10-25T18:32:21Z",
"aliases": [
"CVE-2023-36085"
@@ -24,13 +24,17 @@
{
"type": "WEB",
"url": "https://github.com/omershaik0/Handmade_Exploits/tree/main/SISQUALWFM-Host-Header-Injection-CVE-2023-36085"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/176991/SISQUAL-WFM-7.1.319.103-Host-Header-Injection.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-601"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-25T18:17:28Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-25g8-7mhh-fm84",
"modified": "2024-01-29T15:30:30Z",
"modified": "2024-02-05T18:31:36Z",
"published": "2024-01-29T15:30:30Z",
"aliases": [
"CVE-2023-7200"
],
"details": "The EventON WordPress plugin before 4.4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-29T15:15:09Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5q2h-m2hm-4r3w",
"modified": "2024-01-24T18:31:01Z",
"modified": "2024-02-05T18:31:36Z",
"published": "2024-01-24T18:31:01Z",
"aliases": [
"CVE-2023-51886"
],
"details": "Buffer Overflow vulnerability in the main() function in Mathtex 1.05 and before allows a remote attacker to cause a denial of service when using \\convertpath.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-24T17:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-663j-9vv5-mmf4",
"modified": "2024-01-24T18:31:01Z",
"modified": "2024-02-05T18:31:36Z",
"published": "2024-01-24T18:31:01Z",
"aliases": [
"CVE-2023-51887"
],
"details": "Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-24T17:15:08Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-89c9-2mcj-c9gr",
"modified": "2024-01-30T09:30:34Z",
"modified": "2024-02-05T18:31:36Z",
"published": "2024-01-30T09:30:34Z",
"aliases": [
"CVE-2024-1061"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8h9j-pxfp-9p97",
"modified": "2024-01-24T18:31:01Z",
"modified": "2024-02-05T18:31:36Z",
"published": "2024-01-24T18:31:01Z",
"aliases": [
"CVE-2023-51885"
],
"details": "Buffer Overflow vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via the length of the LaTeX string component.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-120"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-24T17:15:08Z"
@@ -28,7 +28,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
"CWE-20",
"CWE-552"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f3p3-3pq5-xp8x",
"modified": "2024-01-29T21:30:27Z",
"modified": "2024-02-05T18:31:36Z",
"published": "2024-01-29T21:30:27Z",
"aliases": [
"CVE-2024-24135"
],
"details": "Product Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to XSS attacks.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-29T19:15:08Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hpcp-jfj7-rjww",
"modified": "2024-01-29T15:30:29Z",
"modified": "2024-02-05T18:31:36Z",
"published": "2024-01-29T15:30:29Z",
"aliases": [
"CVE-2023-5124"
],
"details": "The Page Builder: Pagelayer WordPress plugin before 1.8.0 doesn't prevent attackers with administrator privileges from inserting malicious JavaScript inside a post's header or footer code, even when unfiltered_html is disallowed, such as in multi-site WordPress configurations.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-29T15:15:09Z"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m653-22c6-v2w8",
"modified": "2024-01-29T15:30:30Z",
"modified": "2024-02-05T18:31:36Z",
"published": "2024-01-29T15:30:30Z",
"aliases": [
"CVE-2023-7204"
],
"details": "The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the cloning process which provides",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -25,9 +28,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-668"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-29T15:15:09Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rq2f-mxxc-3hv5",
"modified": "2024-01-30T03:30:30Z",
"modified": "2024-02-05T18:31:36Z",
"published": "2024-01-30T03:30:30Z",
"aliases": [
"CVE-2023-37571"
],
"details": "Softing TH SCOPE through 3.70 allows XSS.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-30T01:15:58Z"
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2cmm-m4c8-c4wp",
"modified": "2024-02-05T18:31:37Z",
"published": "2024-02-05T18:31:37Z",
"aliases": [
"CVE-2024-24263"
],
"details": "Lotos WebServer v0.1.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the response_append_status_line function at /lotos/src/response.c.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24263"
},
{
"type": "WEB",
"url": "https://github.com/LuMingYinDetect/lotos_detects/blob/main/lotos_detect_1.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-05T18:15:52Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2qm8-4j25-v4w6",
"modified": "2024-02-05T18:31:37Z",
"published": "2024-02-05T18:31:37Z",
"aliases": [
"CVE-2024-24265"
],
"details": "gpac v2.2.1 was discovered to contain a memory leak via the dst_props variable in the gf_filter_pid_merge_properties_internal function.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24265"
},
{
"type": "WEB",
"url": "https://github.com/yinluming13579/gpac_defects/blob/main/gpac_1.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-05T18:15:52Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-34rx-mprw-whv5",
"modified": "2024-02-05T18:31:37Z",
"published": "2024-02-05T18:31:37Z",
"aliases": [
"CVE-2024-23054"
],
"details": "An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components not existing in the public package index (npm).",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23054"
},
{
"type": "WEB",
"url": "https://github.com/c0d3x27/CVEs/blob/main/CVE-2024-23054/README.md"
},
{
"type": "WEB",
"url": "http://plone.com"
},
{
"type": "WEB",
"url": "http://ploneorg.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-05T16:15:55Z"
}
}

Some files were not shown because too many files have changed in this diff Show More