Publish Advisories

GHSA-6mw8-979h-4g47
GHSA-92r5-9pqm-cxcj
GHSA-ccc2-7fh4-pj2x
GHSA-fmf9-8vg2-mj5m
GHSA-g6fv-r8qr-2wv7
GHSA-jf6x-c677-9359
GHSA-vgqv-q7r5-8p24
This commit is contained in:
advisory-database[bot]
2024-03-15 06:32:03 +00:00
parent fb904b1098
commit e64ab2be16
7 changed files with 303 additions and 0 deletions
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6mw8-979h-4g47",
"modified": "2024-03-15T06:30:34Z",
"published": "2024-03-15T06:30:34Z",
"aliases": [
"CVE-2024-2481"
],
"details": "A vulnerability, which was classified as critical, was found in Surya2Developer Hostel Management System 1.0. Affected is an unknown function of the file /admin/manage-students.php. The manipulation of the argument del leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-256890 is the identifier assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2481"
},
{
"type": "WEB",
"url": "https://github.com/blackslim3/cve_sidequest/blob/main/poc/Broken_Access_Control%20on%20Hostel%20Management%20System%20using%20PHP%20and%20MySQL%201.0.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.256890"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.256890"
}
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T06:15:11Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-92r5-9pqm-cxcj",
"modified": "2024-03-15T06:30:34Z",
"published": "2024-03-15T06:30:34Z",
"aliases": [
"CVE-2024-2480"
],
"details": "A vulnerability classified as critical was found in MHA Sistemas arMHAzena 9.6.0.0. This vulnerability affects unknown code of the component Executa Page. The manipulation of the argument Companhia/Planta/Agente de/Agente até leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-256888. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2480"
},
{
"type": "WEB",
"url": "https://johnermac.github.io/cve/sqli"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.256888"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.256888"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T06:15:10Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ccc2-7fh4-pj2x",
"modified": "2024-03-15T06:30:33Z",
"published": "2024-03-15T06:30:33Z",
"aliases": [
"CVE-2024-25227"
],
"details": "SQL Injection vulnerability in ABO.CMS version 5.8, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via the tb_login parameter in admin login page.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25227"
},
{
"type": "WEB",
"url": "https://thetrueartist.wixsite.com/cveblog/post/understanding-the-potential-impact-of-cve-2024-25227-what-you-need-to-know-and-how-it-was-discovered"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T06:15:08Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fmf9-8vg2-mj5m",
"modified": "2024-03-15T06:30:34Z",
"published": "2024-03-15T06:30:33Z",
"aliases": [
"CVE-2024-2479"
],
"details": "A vulnerability classified as problematic has been found in MHA Sistemas arMHAzena 9.6.0.0. This affects an unknown part of the component Cadastro Page. The manipulation of the argument Query leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-256887. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2479"
},
{
"type": "WEB",
"url": "https://johnermac.github.io/cve/xss"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.256887"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.256887"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T06:15:10Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g6fv-r8qr-2wv7",
"modified": "2024-03-15T06:30:33Z",
"published": "2024-03-15T06:30:33Z",
"aliases": [
"CVE-2024-2204"
],
"details": "Zemana AntiLogger v2.74.204.664 is vulnerable to a Denial of Service (DoS) vulnerability by triggering the 0x80002004 and 0x80002010 IOCTL codes of the zam64.sys and zamguard64.sys drivers.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2204"
},
{
"type": "WEB",
"url": "https://fluidattacks.com/advisories/hassan"
},
{
"type": "WEB",
"url": "https://zemana.com/us/antilogger.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-476"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T05:15:07Z"
}
}
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jf6x-c677-9359",
"modified": "2024-03-15T06:30:33Z",
"published": "2024-03-15T06:30:33Z",
"aliases": [
"CVE-2024-2478"
],
"details": "A vulnerability was found in BradWenqiang HR 2.0. It has been rated as critical. Affected by this issue is the function selectAll of the file /bishe/register of the component Background Management. The manipulation of the argument userName leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-256886 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2478"
},
{
"type": "WEB",
"url": "https://github.com/zuizui35/cve/blob/main/cve.md"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.256886"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.256886"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T06:15:09Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vgqv-q7r5-8p24",
"modified": "2024-03-15T06:30:33Z",
"published": "2024-03-15T06:30:33Z",
"aliases": [
"CVE-2024-2180"
],
"details": "Zemana AntiLogger v2.74.204.664 is vulnerable to a Memory Information Leak vulnerability by triggering the 0x80002020 IOCTL code of the zam64.sys and zamguard64.sys drivers",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2180"
},
{
"type": "WEB",
"url": "https://fluidattacks.com/advisories/gomez"
},
{
"type": "WEB",
"url": "https://zemana.com/us/antilogger.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-15T05:15:06Z"
}
}