From f7e9859e78e9cd5bfa056280fd138a11f6338e03 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 28 Dec 2023 22:13:09 +0000 Subject: [PATCH] Publish GHSA-87fg-9x5w-j3rm --- .../GHSA-87fg-9x5w-j3rm.json | 38 +++++++++++++++++-- 1 file changed, 34 insertions(+), 4 deletions(-) rename advisories/{unreviewed => github-reviewed}/2023/12/GHSA-87fg-9x5w-j3rm/GHSA-87fg-9x5w-j3rm.json (55%) diff --git a/advisories/unreviewed/2023/12/GHSA-87fg-9x5w-j3rm/GHSA-87fg-9x5w-j3rm.json b/advisories/github-reviewed/2023/12/GHSA-87fg-9x5w-j3rm/GHSA-87fg-9x5w-j3rm.json similarity index 55% rename from advisories/unreviewed/2023/12/GHSA-87fg-9x5w-j3rm/GHSA-87fg-9x5w-j3rm.json rename to advisories/github-reviewed/2023/12/GHSA-87fg-9x5w-j3rm/GHSA-87fg-9x5w-j3rm.json index ce76defafbf..8237da40892 100644 --- a/advisories/unreviewed/2023/12/GHSA-87fg-9x5w-j3rm/GHSA-87fg-9x5w-j3rm.json +++ b/advisories/github-reviewed/2023/12/GHSA-87fg-9x5w-j3rm/GHSA-87fg-9x5w-j3rm.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-87fg-9x5w-j3rm", - "modified": "2023-12-28T21:30:38Z", + "modified": "2023-12-28T22:11:55Z", "published": "2023-12-20T15:30:19Z", "aliases": [ "CVE-2023-38519" ], + "summary": "MainWP Dashboard SQL Command Injection vulnerability", "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MainWP MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance.This issue affects MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance: from n/a through 4.4.3.3.\n\n", "severity": [ { @@ -14,13 +15,42 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "mainwp/mainwp" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.4.3.4" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 4.4.3.3" + } + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38519" }, + { + "type": "WEB", + "url": "https://github.com/mainwp/mainwp/commit/8df951c0e8b2c2646cc57fc66b00767551cac400" + }, + { + "type": "PACKAGE", + "url": "https://github.com/mainwp/mainwp" + }, { "type": "WEB", "url": "https://patchstack.com/database/vulnerability/mainwp/wordpress-mainwp-plugin-4-4-3-3-sql-injection-vulnerability?_s_id=cve" @@ -31,8 +61,8 @@ "CWE-89" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2023-12-28T22:11:55Z", "nvd_published_at": "2023-12-20T14:15:19Z" } } \ No newline at end of file