From f132f1346400bc0ded128615f7d0c67fbb6953bb Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 22 May 2024 15:32:25 +0000 Subject: [PATCH] Publish Advisories GHSA-42g6-fx4g-4pxv GHSA-4rj5-hv6x-v84g GHSA-85f4-3cvc-fmrq GHSA-924x-9wjq-6fqr GHSA-9cm6-r59j-22jc GHSA-9rr6-j7h7-p29p GHSA-c8h5-gmvf-fxhw GHSA-cr2c-p6wc-8hfh GHSA-cx9m-x7w8-76m2 GHSA-fpmf-fc9x-9w73 GHSA-h9h4-qmr7-m6fj GHSA-j9h6-5r2h-wq4m GHSA-jq74-w56w-cjqw GHSA-mgj2-4fwc-v47j GHSA-mm62-pv5h-xg4v GHSA-pc2v-g9xh-4hcw GHSA-r8g7-9pvc-p6p6 GHSA-rm96-h83h-vg96 GHSA-v4m9-9x56-7gh6 GHSA-v5pv-v2xp-jjp2 GHSA-v5r5-978f-9w52 --- .../GHSA-42g6-fx4g-4pxv.json | 35 ++++++++++++++ .../GHSA-4rj5-hv6x-v84g.json | 46 +++++++++++++++++++ .../GHSA-85f4-3cvc-fmrq.json | 35 ++++++++++++++ .../GHSA-924x-9wjq-6fqr.json | 35 ++++++++++++++ .../GHSA-9cm6-r59j-22jc.json | 35 ++++++++++++++ .../GHSA-9rr6-j7h7-p29p.json | 35 ++++++++++++++ .../GHSA-c8h5-gmvf-fxhw.json | 35 ++++++++++++++ .../GHSA-cr2c-p6wc-8hfh.json | 2 +- .../GHSA-cx9m-x7w8-76m2.json | 35 ++++++++++++++ .../GHSA-fpmf-fc9x-9w73.json | 35 ++++++++++++++ .../GHSA-h9h4-qmr7-m6fj.json | 35 ++++++++++++++ .../GHSA-j9h6-5r2h-wq4m.json | 35 ++++++++++++++ .../GHSA-jq74-w56w-cjqw.json | 35 ++++++++++++++ .../GHSA-mgj2-4fwc-v47j.json | 35 ++++++++++++++ .../GHSA-mm62-pv5h-xg4v.json | 35 ++++++++++++++ .../GHSA-pc2v-g9xh-4hcw.json | 35 ++++++++++++++ .../GHSA-r8g7-9pvc-p6p6.json | 35 ++++++++++++++ .../GHSA-rm96-h83h-vg96.json | 35 ++++++++++++++ .../GHSA-v4m9-9x56-7gh6.json | 42 +++++++++++++++++ .../GHSA-v5pv-v2xp-jjp2.json | 35 ++++++++++++++ .../GHSA-v5r5-978f-9w52.json | 35 ++++++++++++++ 21 files changed, 719 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2024/05/GHSA-42g6-fx4g-4pxv/GHSA-42g6-fx4g-4pxv.json create mode 100644 advisories/unreviewed/2024/05/GHSA-4rj5-hv6x-v84g/GHSA-4rj5-hv6x-v84g.json create mode 100644 advisories/unreviewed/2024/05/GHSA-85f4-3cvc-fmrq/GHSA-85f4-3cvc-fmrq.json create mode 100644 advisories/unreviewed/2024/05/GHSA-924x-9wjq-6fqr/GHSA-924x-9wjq-6fqr.json create mode 100644 advisories/unreviewed/2024/05/GHSA-9cm6-r59j-22jc/GHSA-9cm6-r59j-22jc.json create mode 100644 advisories/unreviewed/2024/05/GHSA-9rr6-j7h7-p29p/GHSA-9rr6-j7h7-p29p.json create mode 100644 advisories/unreviewed/2024/05/GHSA-c8h5-gmvf-fxhw/GHSA-c8h5-gmvf-fxhw.json create mode 100644 advisories/unreviewed/2024/05/GHSA-cx9m-x7w8-76m2/GHSA-cx9m-x7w8-76m2.json create mode 100644 advisories/unreviewed/2024/05/GHSA-fpmf-fc9x-9w73/GHSA-fpmf-fc9x-9w73.json create mode 100644 advisories/unreviewed/2024/05/GHSA-h9h4-qmr7-m6fj/GHSA-h9h4-qmr7-m6fj.json create mode 100644 advisories/unreviewed/2024/05/GHSA-j9h6-5r2h-wq4m/GHSA-j9h6-5r2h-wq4m.json create mode 100644 advisories/unreviewed/2024/05/GHSA-jq74-w56w-cjqw/GHSA-jq74-w56w-cjqw.json create mode 100644 advisories/unreviewed/2024/05/GHSA-mgj2-4fwc-v47j/GHSA-mgj2-4fwc-v47j.json create mode 100644 advisories/unreviewed/2024/05/GHSA-mm62-pv5h-xg4v/GHSA-mm62-pv5h-xg4v.json create mode 100644 advisories/unreviewed/2024/05/GHSA-pc2v-g9xh-4hcw/GHSA-pc2v-g9xh-4hcw.json create mode 100644 advisories/unreviewed/2024/05/GHSA-r8g7-9pvc-p6p6/GHSA-r8g7-9pvc-p6p6.json create mode 100644 advisories/unreviewed/2024/05/GHSA-rm96-h83h-vg96/GHSA-rm96-h83h-vg96.json create mode 100644 advisories/unreviewed/2024/05/GHSA-v4m9-9x56-7gh6/GHSA-v4m9-9x56-7gh6.json create mode 100644 advisories/unreviewed/2024/05/GHSA-v5pv-v2xp-jjp2/GHSA-v5pv-v2xp-jjp2.json create mode 100644 advisories/unreviewed/2024/05/GHSA-v5r5-978f-9w52/GHSA-v5r5-978f-9w52.json diff --git a/advisories/unreviewed/2024/05/GHSA-42g6-fx4g-4pxv/GHSA-42g6-fx4g-4pxv.json b/advisories/unreviewed/2024/05/GHSA-42g6-fx4g-4pxv/GHSA-42g6-fx4g-4pxv.json new file mode 100644 index 00000000000..482c2b52ac2 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-42g6-fx4g-4pxv/GHSA-42g6-fx4g-4pxv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42g6-fx4g-4pxv", + "modified": "2024-05-22T15:31:01Z", + "published": "2024-05-22T15:31:01Z", + "aliases": [ + "CVE-2024-33219" + ], + "details": "An issue in the component AsIO64.sys of ASUSTeK Computer Inc ASUS SABERTOOTH X99 Driver v1.0.1.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33219" + }, + { + "type": "WEB", + "url": "https://github.com/DriverHunter/Win-Driver-EXP/tree/main/CVE-2024-33219" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-4rj5-hv6x-v84g/GHSA-4rj5-hv6x-v84g.json b/advisories/unreviewed/2024/05/GHSA-4rj5-hv6x-v84g/GHSA-4rj5-hv6x-v84g.json new file mode 100644 index 00000000000..8bd89a6b844 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-4rj5-hv6x-v84g/GHSA-4rj5-hv6x-v84g.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rj5-hv6x-v84g", + "modified": "2024-05-22T15:31:01Z", + "published": "2024-05-22T15:31:01Z", + "aliases": [ + "CVE-2024-3926" + ], + "details": "The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_attributes value in widgets in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3926" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/tags/5.6.0/modules/creative-button/widgets/creative-button.php#L648" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3066178" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f931cf8e-01dd-4f0b-ac86-6e0654fd1597?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-85f4-3cvc-fmrq/GHSA-85f4-3cvc-fmrq.json b/advisories/unreviewed/2024/05/GHSA-85f4-3cvc-fmrq/GHSA-85f4-3cvc-fmrq.json new file mode 100644 index 00000000000..ba9268fba7b --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-85f4-3cvc-fmrq/GHSA-85f4-3cvc-fmrq.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85f4-3cvc-fmrq", + "modified": "2024-05-22T15:31:00Z", + "published": "2024-05-22T15:31:00Z", + "aliases": [ + "CVE-2024-35475" + ], + "details": "A Cross-Site Request Forgery (CSRF) vulnerability was discovered in OpenKM Community Edition on or before version 6.3.12. The vulnerability exists in /admin/DatabaseQuery, which allows an attacker to manipulate a victim with administrative privileges to execute arbitrary SQL commands.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35475" + }, + { + "type": "WEB", + "url": "https://github.com/carsonchan12345/OpenKM-CSRF-PoC" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-924x-9wjq-6fqr/GHSA-924x-9wjq-6fqr.json b/advisories/unreviewed/2024/05/GHSA-924x-9wjq-6fqr/GHSA-924x-9wjq-6fqr.json new file mode 100644 index 00000000000..ecf8a40df7a --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-924x-9wjq-6fqr/GHSA-924x-9wjq-6fqr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-924x-9wjq-6fqr", + "modified": "2024-05-22T15:31:01Z", + "published": "2024-05-22T15:31:01Z", + "aliases": [ + "CVE-2024-35560" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=del&dataType=&dataTypeCN.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35560" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/25/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-9cm6-r59j-22jc/GHSA-9cm6-r59j-22jc.json b/advisories/unreviewed/2024/05/GHSA-9cm6-r59j-22jc/GHSA-9cm6-r59j-22jc.json new file mode 100644 index 00000000000..da1bd59cf9f --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-9cm6-r59j-22jc/GHSA-9cm6-r59j-22jc.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cm6-r59j-22jc", + "modified": "2024-05-22T15:31:01Z", + "published": "2024-05-22T15:31:01Z", + "aliases": [ + "CVE-2024-35561" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=add&nohrefStr=close.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35561" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/23/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-9rr6-j7h7-p29p/GHSA-9rr6-j7h7-p29p.json b/advisories/unreviewed/2024/05/GHSA-9rr6-j7h7-p29p/GHSA-9rr6-j7h7-p29p.json new file mode 100644 index 00000000000..900e8b7efc9 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-9rr6-j7h7-p29p/GHSA-9rr6-j7h7-p29p.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rr6-j7h7-p29p", + "modified": "2024-05-22T15:31:00Z", + "published": "2024-05-22T15:31:00Z", + "aliases": [ + "CVE-2024-35553" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=add&nohrefStr=close.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35553" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/21/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-c8h5-gmvf-fxhw/GHSA-c8h5-gmvf-fxhw.json b/advisories/unreviewed/2024/05/GHSA-c8h5-gmvf-fxhw/GHSA-c8h5-gmvf-fxhw.json new file mode 100644 index 00000000000..32e304bcbef --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-c8h5-gmvf-fxhw/GHSA-c8h5-gmvf-fxhw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8h5-gmvf-fxhw", + "modified": "2024-05-22T15:31:01Z", + "published": "2024-05-22T15:31:01Z", + "aliases": [ + "CVE-2024-33218" + ], + "details": "An issue in the component AsUpIO64.sys of ASUSTeK Computer Inc ASUS USB 3.0 Boost Storage Driver 5.30.20.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33218" + }, + { + "type": "WEB", + "url": "https://github.com/DriverHunter/Win-Driver-EXP/tree/main/CVE-2024-33218" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-cr2c-p6wc-8hfh/GHSA-cr2c-p6wc-8hfh.json b/advisories/unreviewed/2024/05/GHSA-cr2c-p6wc-8hfh/GHSA-cr2c-p6wc-8hfh.json index 78f7a03a223..a3b86bf5988 100644 --- a/advisories/unreviewed/2024/05/GHSA-cr2c-p6wc-8hfh/GHSA-cr2c-p6wc-8hfh.json +++ b/advisories/unreviewed/2024/05/GHSA-cr2c-p6wc-8hfh/GHSA-cr2c-p6wc-8hfh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cr2c-p6wc-8hfh", - "modified": "2024-05-22T12:32:28Z", + "modified": "2024-05-22T15:30:59Z", "published": "2024-05-22T12:32:28Z", "aliases": [ "CVE-2024-36010" diff --git a/advisories/unreviewed/2024/05/GHSA-cx9m-x7w8-76m2/GHSA-cx9m-x7w8-76m2.json b/advisories/unreviewed/2024/05/GHSA-cx9m-x7w8-76m2/GHSA-cx9m-x7w8-76m2.json new file mode 100644 index 00000000000..2a8170d2e41 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-cx9m-x7w8-76m2/GHSA-cx9m-x7w8-76m2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx9m-x7w8-76m2", + "modified": "2024-05-22T15:31:01Z", + "published": "2024-05-22T15:31:01Z", + "aliases": [ + "CVE-2024-33220" + ], + "details": "An issue in the component AslO3_64.sys of ASUSTeK Computer Inc AISuite3 v3.03.36 3.03.36 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33220" + }, + { + "type": "WEB", + "url": "https://github.com/DriverHunter/Win-Driver-EXP/tree/main/CVE-2024-33220" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-fpmf-fc9x-9w73/GHSA-fpmf-fc9x-9w73.json b/advisories/unreviewed/2024/05/GHSA-fpmf-fc9x-9w73/GHSA-fpmf-fc9x-9w73.json new file mode 100644 index 00000000000..933ac032f37 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-fpmf-fc9x-9w73/GHSA-fpmf-fc9x-9w73.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpmf-fc9x-9w73", + "modified": "2024-05-22T15:31:01Z", + "published": "2024-05-22T15:31:01Z", + "aliases": [ + "CVE-2024-33221" + ], + "details": "An issue in the component AsusBSItf.sys of ASUSTeK Computer Inc ASUS BIOS Flash Driver v3.2.12.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33221" + }, + { + "type": "WEB", + "url": "https://github.com/DriverHunter/Win-Driver-EXP/tree/main/CVE-2024-33221" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T15:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-h9h4-qmr7-m6fj/GHSA-h9h4-qmr7-m6fj.json b/advisories/unreviewed/2024/05/GHSA-h9h4-qmr7-m6fj/GHSA-h9h4-qmr7-m6fj.json new file mode 100644 index 00000000000..c6d5da69429 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-h9h4-qmr7-m6fj/GHSA-h9h4-qmr7-m6fj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9h4-qmr7-m6fj", + "modified": "2024-05-22T15:31:00Z", + "published": "2024-05-22T15:31:00Z", + "aliases": [ + "CVE-2024-35555" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/share_switch.php?mudi=switch&dataType=newsWeb&fieldName=state&fieldName2=state&tabName=infoWeb&dataID=40.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35555" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/18/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-j9h6-5r2h-wq4m/GHSA-j9h6-5r2h-wq4m.json b/advisories/unreviewed/2024/05/GHSA-j9h6-5r2h-wq4m/GHSA-j9h6-5r2h-wq4m.json new file mode 100644 index 00000000000..220fb9dd513 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-j9h6-5r2h-wq4m/GHSA-j9h6-5r2h-wq4m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9h6-5r2h-wq4m", + "modified": "2024-05-22T15:31:00Z", + "published": "2024-05-22T15:31:00Z", + "aliases": [ + "CVE-2024-35552" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=del&dataType=logo&dataTypeCN.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35552" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/20/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-jq74-w56w-cjqw/GHSA-jq74-w56w-cjqw.json b/advisories/unreviewed/2024/05/GHSA-jq74-w56w-cjqw/GHSA-jq74-w56w-cjqw.json new file mode 100644 index 00000000000..b25a8607a23 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-jq74-w56w-cjqw/GHSA-jq74-w56w-cjqw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq74-w56w-cjqw", + "modified": "2024-05-22T15:31:01Z", + "published": "2024-05-22T15:31:01Z", + "aliases": [ + "CVE-2024-35559" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=rev&nohrefStr=close.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35559" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/22/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-mgj2-4fwc-v47j/GHSA-mgj2-4fwc-v47j.json b/advisories/unreviewed/2024/05/GHSA-mgj2-4fwc-v47j/GHSA-mgj2-4fwc-v47j.json new file mode 100644 index 00000000000..06137159b86 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-mgj2-4fwc-v47j/GHSA-mgj2-4fwc-v47j.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgj2-4fwc-v47j", + "modified": "2024-05-22T15:30:59Z", + "published": "2024-05-22T15:30:59Z", + "aliases": [ + "CVE-2024-35409" + ], + "details": "WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35409" + }, + { + "type": "WEB", + "url": "https://github.com/ixpqxi/CVE_LIST/blob/master/WeBid_sqli/WeBid_v1.1.2_sql_injection_vulnerability.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-mm62-pv5h-xg4v/GHSA-mm62-pv5h-xg4v.json b/advisories/unreviewed/2024/05/GHSA-mm62-pv5h-xg4v/GHSA-mm62-pv5h-xg4v.json new file mode 100644 index 00000000000..db0bb5fd9d4 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-mm62-pv5h-xg4v/GHSA-mm62-pv5h-xg4v.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm62-pv5h-xg4v", + "modified": "2024-05-22T15:31:00Z", + "published": "2024-05-22T15:31:00Z", + "aliases": [ + "CVE-2024-35551" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=add.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35551" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/16/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-pc2v-g9xh-4hcw/GHSA-pc2v-g9xh-4hcw.json b/advisories/unreviewed/2024/05/GHSA-pc2v-g9xh-4hcw/GHSA-pc2v-g9xh-4hcw.json new file mode 100644 index 00000000000..2ae60b28d1e --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-pc2v-g9xh-4hcw/GHSA-pc2v-g9xh-4hcw.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc2v-g9xh-4hcw", + "modified": "2024-05-22T15:31:01Z", + "published": "2024-05-22T15:31:00Z", + "aliases": [ + "CVE-2024-35557" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsApi_deal.php?mudi=rev&nohrefStr=close.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35557" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/27/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-r8g7-9pvc-p6p6/GHSA-r8g7-9pvc-p6p6.json b/advisories/unreviewed/2024/05/GHSA-r8g7-9pvc-p6p6/GHSA-r8g7-9pvc-p6p6.json new file mode 100644 index 00000000000..30e3a08da4d --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-r8g7-9pvc-p6p6/GHSA-r8g7-9pvc-p6p6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8g7-9pvc-p6p6", + "modified": "2024-05-22T15:31:01Z", + "published": "2024-05-22T15:31:01Z", + "aliases": [ + "CVE-2024-35558" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=rev&nohrefStr=close.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35558" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/24/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-rm96-h83h-vg96/GHSA-rm96-h83h-vg96.json b/advisories/unreviewed/2024/05/GHSA-rm96-h83h-vg96/GHSA-rm96-h83h-vg96.json new file mode 100644 index 00000000000..d86f22f6cff --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-rm96-h83h-vg96/GHSA-rm96-h83h-vg96.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rm96-h83h-vg96", + "modified": "2024-05-22T15:31:00Z", + "published": "2024-05-22T15:31:00Z", + "aliases": [ + "CVE-2024-35550" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=rev.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35550" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/17/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-v4m9-9x56-7gh6/GHSA-v4m9-9x56-7gh6.json b/advisories/unreviewed/2024/05/GHSA-v4m9-9x56-7gh6/GHSA-v4m9-9x56-7gh6.json new file mode 100644 index 00000000000..399fdd9b78e --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-v4m9-9x56-7gh6/GHSA-v4m9-9x56-7gh6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4m9-9x56-7gh6", + "modified": "2024-05-22T15:30:59Z", + "published": "2024-05-22T15:30:59Z", + "aliases": [ + "CVE-2024-4261" + ], + "details": "The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4261" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/lead-form-builder/trunk/block/app.php#L24" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/858d8641-7455-47c2-9639-480ce4ec3540?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T13:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-v5pv-v2xp-jjp2/GHSA-v5pv-v2xp-jjp2.json b/advisories/unreviewed/2024/05/GHSA-v5pv-v2xp-jjp2/GHSA-v5pv-v2xp-jjp2.json new file mode 100644 index 00000000000..4a583d8f285 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-v5pv-v2xp-jjp2/GHSA-v5pv-v2xp-jjp2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5pv-v2xp-jjp2", + "modified": "2024-05-22T15:31:00Z", + "published": "2024-05-22T15:31:00Z", + "aliases": [ + "CVE-2024-35554" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=del&dataType=newsWeb&dataTypeCN.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35554" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/19/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-v5r5-978f-9w52/GHSA-v5r5-978f-9w52.json b/advisories/unreviewed/2024/05/GHSA-v5r5-978f-9w52/GHSA-v5r5-978f-9w52.json new file mode 100644 index 00000000000..c21f0c54fa1 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-v5r5-978f-9w52/GHSA-v5r5-978f-9w52.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5r5-978f-9w52", + "modified": "2024-05-22T15:31:00Z", + "published": "2024-05-22T15:31:00Z", + "aliases": [ + "CVE-2024-35556" + ], + "details": "idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsSys_deal.php?mudi=infoSet.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35556" + }, + { + "type": "WEB", + "url": "https://github.com/bearman113/1.md/blob/main/26/csrf.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T14:15:09Z" + } +} \ No newline at end of file