From e3e96549ddfb9b154168424f5da83626bba17bb7 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 13 Aug 2024 12:32:03 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-25f7-hgg7-xwpg.json | 38 +++++++++++++++++ .../GHSA-25fr-pq5j-rg59.json | 38 +++++++++++++++++ .../GHSA-28c6-pjxj-5qxg.json | 42 +++++++++++++++++++ .../GHSA-32w5-785v-xx4q.json | 38 +++++++++++++++++ .../GHSA-4299-pp5c-6rgf.json | 38 +++++++++++++++++ .../GHSA-4px4-8gjq-r2q2.json | 38 +++++++++++++++++ .../GHSA-4x6g-78gw-mgr8.json | 38 +++++++++++++++++ .../GHSA-576m-857x-xpjm.json | 38 +++++++++++++++++ .../GHSA-576r-2w3j-qph3.json | 38 +++++++++++++++++ .../GHSA-5pr3-frh5-5p66.json | 38 +++++++++++++++++ .../GHSA-66p4-8wjq-58rp.json | 38 +++++++++++++++++ .../GHSA-69p5-4jp4-c55r.json | 38 +++++++++++++++++ .../GHSA-732m-w9mm-p8pc.json | 38 +++++++++++++++++ .../GHSA-7fgx-pmw9-49h5.json | 38 +++++++++++++++++ .../GHSA-7g53-9qw7-jg2j.json | 38 +++++++++++++++++ .../GHSA-7pc7-hfxf-c22q.json | 38 +++++++++++++++++ .../GHSA-9xjx-64hw-fp62.json | 38 +++++++++++++++++ .../GHSA-c92m-668g-h9mv.json | 38 +++++++++++++++++ .../GHSA-ccfc-25xc-jwxh.json | 42 +++++++++++++++++++ .../GHSA-hmq8-xvrm-7xqj.json | 38 +++++++++++++++++ .../GHSA-j4xj-8c96-39jq.json | 38 +++++++++++++++++ .../GHSA-jfcj-w3xj-hw99.json | 38 +++++++++++++++++ .../GHSA-qc7c-w5wc-8wrh.json | 38 +++++++++++++++++ .../GHSA-v6j4-8hq4-f7g4.json | 38 +++++++++++++++++ .../GHSA-vc9g-8jrm-c9w6.json | 38 +++++++++++++++++ .../GHSA-w6vh-92xv-xgjf.json | 42 +++++++++++++++++++ .../GHSA-xf46-hjp6-hxpp.json | 38 +++++++++++++++++ .../GHSA-xfgq-g492-6m25.json | 38 +++++++++++++++++ .../GHSA-xqhm-wm3p-7wv9.json | 38 +++++++++++++++++ 29 files changed, 1114 insertions(+) create mode 100644 advisories/unreviewed/2024/08/GHSA-25f7-hgg7-xwpg/GHSA-25f7-hgg7-xwpg.json create mode 100644 advisories/unreviewed/2024/08/GHSA-25fr-pq5j-rg59/GHSA-25fr-pq5j-rg59.json create mode 100644 advisories/unreviewed/2024/08/GHSA-28c6-pjxj-5qxg/GHSA-28c6-pjxj-5qxg.json create mode 100644 advisories/unreviewed/2024/08/GHSA-32w5-785v-xx4q/GHSA-32w5-785v-xx4q.json create mode 100644 advisories/unreviewed/2024/08/GHSA-4299-pp5c-6rgf/GHSA-4299-pp5c-6rgf.json create mode 100644 advisories/unreviewed/2024/08/GHSA-4px4-8gjq-r2q2/GHSA-4px4-8gjq-r2q2.json create mode 100644 advisories/unreviewed/2024/08/GHSA-4x6g-78gw-mgr8/GHSA-4x6g-78gw-mgr8.json create mode 100644 advisories/unreviewed/2024/08/GHSA-576m-857x-xpjm/GHSA-576m-857x-xpjm.json create mode 100644 advisories/unreviewed/2024/08/GHSA-576r-2w3j-qph3/GHSA-576r-2w3j-qph3.json create mode 100644 advisories/unreviewed/2024/08/GHSA-5pr3-frh5-5p66/GHSA-5pr3-frh5-5p66.json create mode 100644 advisories/unreviewed/2024/08/GHSA-66p4-8wjq-58rp/GHSA-66p4-8wjq-58rp.json create mode 100644 advisories/unreviewed/2024/08/GHSA-69p5-4jp4-c55r/GHSA-69p5-4jp4-c55r.json create mode 100644 advisories/unreviewed/2024/08/GHSA-732m-w9mm-p8pc/GHSA-732m-w9mm-p8pc.json create mode 100644 advisories/unreviewed/2024/08/GHSA-7fgx-pmw9-49h5/GHSA-7fgx-pmw9-49h5.json create mode 100644 advisories/unreviewed/2024/08/GHSA-7g53-9qw7-jg2j/GHSA-7g53-9qw7-jg2j.json create mode 100644 advisories/unreviewed/2024/08/GHSA-7pc7-hfxf-c22q/GHSA-7pc7-hfxf-c22q.json create mode 100644 advisories/unreviewed/2024/08/GHSA-9xjx-64hw-fp62/GHSA-9xjx-64hw-fp62.json create mode 100644 advisories/unreviewed/2024/08/GHSA-c92m-668g-h9mv/GHSA-c92m-668g-h9mv.json create mode 100644 advisories/unreviewed/2024/08/GHSA-ccfc-25xc-jwxh/GHSA-ccfc-25xc-jwxh.json create mode 100644 advisories/unreviewed/2024/08/GHSA-hmq8-xvrm-7xqj/GHSA-hmq8-xvrm-7xqj.json create mode 100644 advisories/unreviewed/2024/08/GHSA-j4xj-8c96-39jq/GHSA-j4xj-8c96-39jq.json create mode 100644 advisories/unreviewed/2024/08/GHSA-jfcj-w3xj-hw99/GHSA-jfcj-w3xj-hw99.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qc7c-w5wc-8wrh/GHSA-qc7c-w5wc-8wrh.json create mode 100644 advisories/unreviewed/2024/08/GHSA-v6j4-8hq4-f7g4/GHSA-v6j4-8hq4-f7g4.json create mode 100644 advisories/unreviewed/2024/08/GHSA-vc9g-8jrm-c9w6/GHSA-vc9g-8jrm-c9w6.json create mode 100644 advisories/unreviewed/2024/08/GHSA-w6vh-92xv-xgjf/GHSA-w6vh-92xv-xgjf.json create mode 100644 advisories/unreviewed/2024/08/GHSA-xf46-hjp6-hxpp/GHSA-xf46-hjp6-hxpp.json create mode 100644 advisories/unreviewed/2024/08/GHSA-xfgq-g492-6m25/GHSA-xfgq-g492-6m25.json create mode 100644 advisories/unreviewed/2024/08/GHSA-xqhm-wm3p-7wv9/GHSA-xqhm-wm3p-7wv9.json diff --git a/advisories/unreviewed/2024/08/GHSA-25f7-hgg7-xwpg/GHSA-25f7-hgg7-xwpg.json b/advisories/unreviewed/2024/08/GHSA-25f7-hgg7-xwpg/GHSA-25f7-hgg7-xwpg.json new file mode 100644 index 00000000000..d9133402f76 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-25f7-hgg7-xwpg/GHSA-25f7-hgg7-xwpg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25f7-hgg7-xwpg", + "modified": "2024-08-13T12:30:53Z", + "published": "2024-08-13T12:30:53Z", + "aliases": [ + "CVE-2024-43121" + ], + "details": "Improper Privilege Management vulnerability in realmag777 HUSKY allows Privilege Escalation.This issue affects HUSKY: from n/a through 1.3.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43121" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce-products-filter/wordpress-husky-plugin-1-3-6-1-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T11:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-25fr-pq5j-rg59/GHSA-25fr-pq5j-rg59.json b/advisories/unreviewed/2024/08/GHSA-25fr-pq5j-rg59/GHSA-25fr-pq5j-rg59.json new file mode 100644 index 00000000000..bf4767c31ba --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-25fr-pq5j-rg59/GHSA-25fr-pq5j-rg59.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25fr-pq5j-rg59", + "modified": "2024-08-13T12:30:51Z", + "published": "2024-08-13T12:30:51Z", + "aliases": [ + "CVE-2024-2259" + ], + "details": "This vulnerability exists in InstaRISPACS software due to insufficient validation of user supplied input for the loginTo parameter in user login module of the web interface of the application. A remote attacker could exploit this vulnerability by sending a specially crafted input to the vulnerable parameter to perform reflected Cross Site Scripting (XSS) attacks on the targeted system.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2259" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0241" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T11:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-28c6-pjxj-5qxg/GHSA-28c6-pjxj-5qxg.json b/advisories/unreviewed/2024/08/GHSA-28c6-pjxj-5qxg/GHSA-28c6-pjxj-5qxg.json new file mode 100644 index 00000000000..efb3a980351 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-28c6-pjxj-5qxg/GHSA-28c6-pjxj-5qxg.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28c6-pjxj-5qxg", + "modified": "2024-08-13T12:30:53Z", + "published": "2024-08-13T12:30:53Z", + "aliases": [ + "CVE-2024-35124" + ], + "details": "A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default password and session management allow an attacker to gain administrative access to the BMC. IBM X-Force ID: 290674.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35124" + }, + { + "type": "WEB", + "url": "https://https://exchange.xforce.ibmcloud.com/vulnerabilities/290674" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7163195" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T12:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-32w5-785v-xx4q/GHSA-32w5-785v-xx4q.json b/advisories/unreviewed/2024/08/GHSA-32w5-785v-xx4q/GHSA-32w5-785v-xx4q.json new file mode 100644 index 00000000000..ad14412add6 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-32w5-785v-xx4q/GHSA-32w5-785v-xx4q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32w5-785v-xx4q", + "modified": "2024-08-13T12:30:52Z", + "published": "2024-08-13T12:30:52Z", + "aliases": [ + "CVE-2024-38756" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Weblizar Coming Soon allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coming Soon: from n/a through 1.6.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38756" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/responsive-coming-soon-page/wordpress-coming-soon-page-responsive-coming-soon-maintenance-mode-plugin-1-6-3-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4299-pp5c-6rgf/GHSA-4299-pp5c-6rgf.json b/advisories/unreviewed/2024/08/GHSA-4299-pp5c-6rgf/GHSA-4299-pp5c-6rgf.json new file mode 100644 index 00000000000..a83ec4e9c9d --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4299-pp5c-6rgf/GHSA-4299-pp5c-6rgf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4299-pp5c-6rgf", + "modified": "2024-08-13T12:30:53Z", + "published": "2024-08-13T12:30:53Z", + "aliases": [ + "CVE-2024-43138" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MagePeople Team Event Manager for WooCommerce allows PHP Local File Inclusion.This issue affects Event Manager for WooCommerce: from n/a through 4.2.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43138" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mage-eventpress/wordpress-event-manager-and-tickets-selling-plugin-for-woocommerce-plugin-4-2-1-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T12:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4px4-8gjq-r2q2/GHSA-4px4-8gjq-r2q2.json b/advisories/unreviewed/2024/08/GHSA-4px4-8gjq-r2q2/GHSA-4px4-8gjq-r2q2.json new file mode 100644 index 00000000000..5bd0f721490 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4px4-8gjq-r2q2/GHSA-4px4-8gjq-r2q2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4px4-8gjq-r2q2", + "modified": "2024-08-13T12:30:51Z", + "published": "2024-08-13T12:30:51Z", + "aliases": [ + "CVE-2024-37935" + ], + "details": "Missing Authorization vulnerability in anhvnit Woocommerce OpenPos allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Woocommerce OpenPos: from n/a through 6.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37935" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce-openpos/wordpress-woocommerce-openpos-plugin-6-4-4-unauthenticated-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T10:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4x6g-78gw-mgr8/GHSA-4x6g-78gw-mgr8.json b/advisories/unreviewed/2024/08/GHSA-4x6g-78gw-mgr8/GHSA-4x6g-78gw-mgr8.json new file mode 100644 index 00000000000..a3387e601f5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4x6g-78gw-mgr8/GHSA-4x6g-78gw-mgr8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x6g-78gw-mgr8", + "modified": "2024-08-13T12:30:53Z", + "published": "2024-08-13T12:30:53Z", + "aliases": [ + "CVE-2024-43129" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper BetterDocs allows PHP Local File Inclusion.This issue affects BetterDocs: from n/a through 3.5.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43129" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/betterdocs/wordpress-betterdocs-plugin-3-5-8-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T11:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-576m-857x-xpjm/GHSA-576m-857x-xpjm.json b/advisories/unreviewed/2024/08/GHSA-576m-857x-xpjm/GHSA-576m-857x-xpjm.json new file mode 100644 index 00000000000..e3f4af4ea56 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-576m-857x-xpjm/GHSA-576m-857x-xpjm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-576m-857x-xpjm", + "modified": "2024-08-13T12:30:52Z", + "published": "2024-08-13T12:30:52Z", + "aliases": [ + "CVE-2024-38749" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Olive Themes Olive One Click Demo Import allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Olive One Click Demo Import: from n/a through 1.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38749" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/olive-one-click-demo-import/wordpress-olive-one-click-demo-import-plugin-1-1-2-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-576r-2w3j-qph3/GHSA-576r-2w3j-qph3.json b/advisories/unreviewed/2024/08/GHSA-576r-2w3j-qph3/GHSA-576r-2w3j-qph3.json new file mode 100644 index 00000000000..85c4de32f49 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-576r-2w3j-qph3/GHSA-576r-2w3j-qph3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-576r-2w3j-qph3", + "modified": "2024-08-13T12:30:52Z", + "published": "2024-08-13T12:30:52Z", + "aliases": [ + "CVE-2024-38760" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in David Maucher Send Users Email allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Send Users Email: from n/a through 1.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38760" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/send-users-email/wordpress-send-users-email-plugin-1-5-1-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5pr3-frh5-5p66/GHSA-5pr3-frh5-5p66.json b/advisories/unreviewed/2024/08/GHSA-5pr3-frh5-5p66/GHSA-5pr3-frh5-5p66.json new file mode 100644 index 00000000000..7458cde1930 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5pr3-frh5-5p66/GHSA-5pr3-frh5-5p66.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pr3-frh5-5p66", + "modified": "2024-08-13T12:30:52Z", + "published": "2024-08-13T12:30:52Z", + "aliases": [ + "CVE-2024-38699" + ], + "details": "Missing Authorization vulnerability in WP Swings Wallet System for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Wallet System for WooCommerce: from n/a through 2.5.13.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38699" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wallet-system-for-woocommerce/wordpress-wallet-system-for-woocommerce-plugin-2-5-13-sensitive-data-exposure-via-exported-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T11:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-66p4-8wjq-58rp/GHSA-66p4-8wjq-58rp.json b/advisories/unreviewed/2024/08/GHSA-66p4-8wjq-58rp/GHSA-66p4-8wjq-58rp.json new file mode 100644 index 00000000000..ce45f2c16fb --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-66p4-8wjq-58rp/GHSA-66p4-8wjq-58rp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66p4-8wjq-58rp", + "modified": "2024-08-13T12:30:51Z", + "published": "2024-08-13T12:30:51Z", + "aliases": [ + "CVE-2024-38688" + ], + "details": "Missing Authorization vulnerability in Igor Benić Recipe Maker For Your Food Blog from Zip Recipes allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Recipe Maker For Your Food Blog from Zip Recipes: from n/a through 8.2.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38688" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/zip-recipes/wordpress-recipe-maker-for-your-food-blog-from-zip-recipes-plugin-8-2-6-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T10:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-69p5-4jp4-c55r/GHSA-69p5-4jp4-c55r.json b/advisories/unreviewed/2024/08/GHSA-69p5-4jp4-c55r/GHSA-69p5-4jp4-c55r.json new file mode 100644 index 00000000000..8b969336600 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-69p5-4jp4-c55r/GHSA-69p5-4jp4-c55r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69p5-4jp4-c55r", + "modified": "2024-08-13T12:30:53Z", + "published": "2024-08-13T12:30:53Z", + "aliases": [ + "CVE-2024-43141" + ], + "details": "Deserialization of Untrusted Data vulnerability in Roland Barker, xnau webdesign Participants Database allows Object Injection.This issue affects Participants Database: from n/a through 2.5.9.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43141" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/participants-database/wordpress-participants-database-plugin-2-5-9-2-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T12:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-732m-w9mm-p8pc/GHSA-732m-w9mm-p8pc.json b/advisories/unreviewed/2024/08/GHSA-732m-w9mm-p8pc/GHSA-732m-w9mm-p8pc.json new file mode 100644 index 00000000000..12b70062864 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-732m-w9mm-p8pc/GHSA-732m-w9mm-p8pc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-732m-w9mm-p8pc", + "modified": "2024-08-13T12:30:53Z", + "published": "2024-08-13T12:30:53Z", + "aliases": [ + "CVE-2024-43153" + ], + "details": "Improper Privilege Management vulnerability in WofficeIO Woffice allows Privilege Escalation.This issue affects Woffice: from n/a through 5.4.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43153" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woffice/wordpress-woffice-theme-5-4-10-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T12:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7fgx-pmw9-49h5/GHSA-7fgx-pmw9-49h5.json b/advisories/unreviewed/2024/08/GHSA-7fgx-pmw9-49h5/GHSA-7fgx-pmw9-49h5.json new file mode 100644 index 00000000000..10ffcf4ebd1 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7fgx-pmw9-49h5/GHSA-7fgx-pmw9-49h5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fgx-pmw9-49h5", + "modified": "2024-08-13T12:30:53Z", + "published": "2024-08-13T12:30:53Z", + "aliases": [ + "CVE-2024-37287" + ], + "details": "A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector features, as well as write access to internal ML indices can trigger a prototype pollution vulnerability, ultimately leading to arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37287" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/kibana-8-14-2-7-17-23-security-update-esa-2024-22" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T12:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7g53-9qw7-jg2j/GHSA-7g53-9qw7-jg2j.json b/advisories/unreviewed/2024/08/GHSA-7g53-9qw7-jg2j/GHSA-7g53-9qw7-jg2j.json new file mode 100644 index 00000000000..759980937f9 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7g53-9qw7-jg2j/GHSA-7g53-9qw7-jg2j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7g53-9qw7-jg2j", + "modified": "2024-08-13T12:30:53Z", + "published": "2024-08-13T12:30:53Z", + "aliases": [ + "CVE-2024-43160" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in BerqWP allows Code Injection.This issue affects BerqWP: from n/a through 1.7.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43160" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/searchpro/wordpress-berqwp-plugin-1-7-6-unauthenticated-arbitrary-file-upload-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T12:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-7pc7-hfxf-c22q/GHSA-7pc7-hfxf-c22q.json b/advisories/unreviewed/2024/08/GHSA-7pc7-hfxf-c22q/GHSA-7pc7-hfxf-c22q.json new file mode 100644 index 00000000000..0e192487922 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7pc7-hfxf-c22q/GHSA-7pc7-hfxf-c22q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pc7-hfxf-c22q", + "modified": "2024-08-13T12:30:54Z", + "published": "2024-08-13T12:30:54Z", + "aliases": [ + "CVE-2024-43165" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rashid87 WPSection allows PHP Local File Inclusion.This issue affects WPSection: from n/a through 1.3.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43165" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wpsection/wordpress-wpsection-plugin-1-3-8-contributor-limited-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T12:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-9xjx-64hw-fp62/GHSA-9xjx-64hw-fp62.json b/advisories/unreviewed/2024/08/GHSA-9xjx-64hw-fp62/GHSA-9xjx-64hw-fp62.json new file mode 100644 index 00000000000..43c1f96fc6e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-9xjx-64hw-fp62/GHSA-9xjx-64hw-fp62.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xjx-64hw-fp62", + "modified": "2024-08-13T12:30:52Z", + "published": "2024-08-13T12:30:52Z", + "aliases": [ + "CVE-2024-38752" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zoho Campaigns allows Cross-Site Scripting (XSS).This issue affects Zoho Campaigns: from n/a through 2.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38752" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/zoho-campaigns/wordpress-zoho-campaigns-plugin-2-0-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T11:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-c92m-668g-h9mv/GHSA-c92m-668g-h9mv.json b/advisories/unreviewed/2024/08/GHSA-c92m-668g-h9mv/GHSA-c92m-668g-h9mv.json new file mode 100644 index 00000000000..b755655d06b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-c92m-668g-h9mv/GHSA-c92m-668g-h9mv.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c92m-668g-h9mv", + "modified": "2024-08-13T12:30:52Z", + "published": "2024-08-13T12:30:52Z", + "aliases": [ + "CVE-2024-39642" + ], + "details": "Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects LearnPress: from n/a through 4.2.6.8.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39642" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/learnpress/wordpress-learnpress-plugin-4-2-6-8-2-insecure-direct-object-references-idor-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-ccfc-25xc-jwxh/GHSA-ccfc-25xc-jwxh.json b/advisories/unreviewed/2024/08/GHSA-ccfc-25xc-jwxh/GHSA-ccfc-25xc-jwxh.json new file mode 100644 index 00000000000..4645f48c238 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-ccfc-25xc-jwxh/GHSA-ccfc-25xc-jwxh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccfc-25xc-jwxh", + "modified": "2024-08-13T12:30:53Z", + "published": "2024-08-13T12:30:53Z", + "aliases": [ + "CVE-2024-41774" + ], + "details": "IBM Common Licensing 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 350348.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41774" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/350348" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7165251" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-hmq8-xvrm-7xqj/GHSA-hmq8-xvrm-7xqj.json b/advisories/unreviewed/2024/08/GHSA-hmq8-xvrm-7xqj/GHSA-hmq8-xvrm-7xqj.json new file mode 100644 index 00000000000..4b7a8685235 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-hmq8-xvrm-7xqj/GHSA-hmq8-xvrm-7xqj.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmq8-xvrm-7xqj", + "modified": "2024-08-13T12:30:53Z", + "published": "2024-08-13T12:30:53Z", + "aliases": [ + "CVE-2024-43128" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in WC Product Table WooCommerce Product Table Lite allows Code Injection.This issue affects WooCommerce Product Table Lite: from n/a through 3.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43128" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wc-product-table-lite/wordpress-woocommerce-product-table-lite-plugin-3-5-1-arbitrary-code-execution-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T11:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j4xj-8c96-39jq/GHSA-j4xj-8c96-39jq.json b/advisories/unreviewed/2024/08/GHSA-j4xj-8c96-39jq/GHSA-j4xj-8c96-39jq.json new file mode 100644 index 00000000000..f67131eb7ae --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j4xj-8c96-39jq/GHSA-j4xj-8c96-39jq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4xj-8c96-39jq", + "modified": "2024-08-13T12:30:52Z", + "published": "2024-08-13T12:30:52Z", + "aliases": [ + "CVE-2024-38787" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Codection Import and export users and customers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Import and export users and customers: from n/a through 1.26.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38787" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/import-users-from-csv-with-meta/wordpress-import-and-export-users-and-customers-plugin-1-26-8-sensitive-information-via-imported-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jfcj-w3xj-hw99/GHSA-jfcj-w3xj-hw99.json b/advisories/unreviewed/2024/08/GHSA-jfcj-w3xj-hw99/GHSA-jfcj-w3xj-hw99.json new file mode 100644 index 00000000000..cacb9138d7b --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-jfcj-w3xj-hw99/GHSA-jfcj-w3xj-hw99.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfcj-w3xj-hw99", + "modified": "2024-08-13T12:30:53Z", + "published": "2024-08-13T12:30:53Z", + "aliases": [ + "CVE-2024-39651" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPWeb WooCommerce PDF Vouchers allows File Manipulation.This issue affects WooCommerce PDF Vouchers: from n/a before 4.9.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39651" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce-pdf-vouchers/wordpress-woocommerce-pdf-vouchers-plugin-4-9-5-unauthenticated-arbitrary-file-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-qc7c-w5wc-8wrh/GHSA-qc7c-w5wc-8wrh.json b/advisories/unreviewed/2024/08/GHSA-qc7c-w5wc-8wrh/GHSA-qc7c-w5wc-8wrh.json new file mode 100644 index 00000000000..4e79682b835 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qc7c-w5wc-8wrh/GHSA-qc7c-w5wc-8wrh.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc7c-w5wc-8wrh", + "modified": "2024-08-13T12:30:52Z", + "published": "2024-08-13T12:30:52Z", + "aliases": [ + "CVE-2024-38747" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HitPay Payment Solutions Pte Ltd HitPay Payment Gateway for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects HitPay Payment Gateway for WooCommerce: from n/a through 4.1.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38747" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/hitpay-payment-gateway/wordpress-hitpay-payment-gateway-for-woocommerce-plugin-4-1-3-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T11:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v6j4-8hq4-f7g4/GHSA-v6j4-8hq4-f7g4.json b/advisories/unreviewed/2024/08/GHSA-v6j4-8hq4-f7g4/GHSA-v6j4-8hq4-f7g4.json new file mode 100644 index 00000000000..fff409c5869 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-v6j4-8hq4-f7g4/GHSA-v6j4-8hq4-f7g4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6j4-8hq4-f7g4", + "modified": "2024-08-13T12:30:52Z", + "published": "2024-08-13T12:30:52Z", + "aliases": [ + "CVE-2024-38724" + ], + "details": "Cross-Site Request Forgery (CSRF), Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Muhammad Rehman Contact Form 7 Summary and Print allows Stored XSS.This issue affects Contact Form 7 Summary and Print: from n/a through 1.2.5.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38724" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cf7-summary-and-print/wordpress-contact-form-7-summary-and-print-plugin-1-2-5-cross-site-request-forgery-csrf-to-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T11:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vc9g-8jrm-c9w6/GHSA-vc9g-8jrm-c9w6.json b/advisories/unreviewed/2024/08/GHSA-vc9g-8jrm-c9w6/GHSA-vc9g-8jrm-c9w6.json new file mode 100644 index 00000000000..760c213d0ad --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vc9g-8jrm-c9w6/GHSA-vc9g-8jrm-c9w6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vc9g-8jrm-c9w6", + "modified": "2024-08-13T12:30:52Z", + "published": "2024-08-13T12:30:52Z", + "aliases": [ + "CVE-2024-38742" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in MBE Worldwide S.P.A. MBE eShip allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MBE eShip: from n/a through 2.1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38742" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/mail-boxes-etc/wordpress-mbe-eship-plugin-2-1-2-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T11:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w6vh-92xv-xgjf/GHSA-w6vh-92xv-xgjf.json b/advisories/unreviewed/2024/08/GHSA-w6vh-92xv-xgjf/GHSA-w6vh-92xv-xgjf.json new file mode 100644 index 00000000000..06d3a5e4c69 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-w6vh-92xv-xgjf/GHSA-w6vh-92xv-xgjf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6vh-92xv-xgjf", + "modified": "2024-08-13T12:30:53Z", + "published": "2024-08-13T12:30:53Z", + "aliases": [ + "CVE-2024-40697" + ], + "details": "IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 297895.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40697" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/297895" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7165250" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-521" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xf46-hjp6-hxpp/GHSA-xf46-hjp6-hxpp.json b/advisories/unreviewed/2024/08/GHSA-xf46-hjp6-hxpp/GHSA-xf46-hjp6-hxpp.json new file mode 100644 index 00000000000..77180837012 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xf46-hjp6-hxpp/GHSA-xf46-hjp6-hxpp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xf46-hjp6-hxpp", + "modified": "2024-08-13T12:30:53Z", + "published": "2024-08-13T12:30:53Z", + "aliases": [ + "CVE-2024-43140" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in G5Theme Ultimate Bootstrap Elements for Elementor allows PHP Local File Inclusion.This issue affects Ultimate Bootstrap Elements for Elementor: from n/a through 1.4.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43140" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ultimate-bootstrap-elements-for-elementor/wordpress-ultimate-bootstrap-elements-for-elementor-plugin-1-4-4-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T12:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xfgq-g492-6m25/GHSA-xfgq-g492-6m25.json b/advisories/unreviewed/2024/08/GHSA-xfgq-g492-6m25/GHSA-xfgq-g492-6m25.json new file mode 100644 index 00000000000..2354ccf8192 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xfgq-g492-6m25/GHSA-xfgq-g492-6m25.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xfgq-g492-6m25", + "modified": "2024-08-13T12:30:53Z", + "published": "2024-08-13T12:30:53Z", + "aliases": [ + "CVE-2024-43135" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allows PHP Local File Inclusion.This issue affects WPCafe: from n/a through 2.2.28.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43135" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-cafe/wordpress-wpcafe-plugin-2-2-28-local-file-inclusion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T11:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-xqhm-wm3p-7wv9/GHSA-xqhm-wm3p-7wv9.json b/advisories/unreviewed/2024/08/GHSA-xqhm-wm3p-7wv9/GHSA-xqhm-wm3p-7wv9.json new file mode 100644 index 00000000000..e00c55a8f2a --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-xqhm-wm3p-7wv9/GHSA-xqhm-wm3p-7wv9.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqhm-wm3p-7wv9", + "modified": "2024-08-13T12:30:53Z", + "published": "2024-08-13T12:30:53Z", + "aliases": [ + "CVE-2024-43131" + ], + "details": "Incorrect Authorization vulnerability in WPWeb Docket (WooCommerce Collections / Wishlist / Watchlist) allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Docket (WooCommerce Collections / Wishlist / Watchlist): from n/a before 1.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43131" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woocommerce-collections/wordpress-docket-woocommerce-collections-wishlist-watchlist-plugin-1-6-6-unauthenticated-arbitrary-post-page-deletion-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-13T11:15:18Z" + } +} \ No newline at end of file