Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-05-19 15:32:02 +00:00
parent 6c0bb60ef5
commit f909756884
127 changed files with 2698 additions and 103 deletions
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fh8c-9pw4-5fjj",
"modified": "2023-11-21T00:30:27Z",
"modified": "2025-05-19T15:30:29Z",
"published": "2023-11-21T00:30:27Z",
"aliases": [
"CVE-2023-6142"
],
"details": "Dev blog v1.0 allows to exploit an XSS through an unrestricted file upload, together with a bad entropy of filenames. With this an attacker can upload a malicious HTML file, then guess the filename of the uploaded file and send it to a potential victim.\n",
"details": "Dev blog v1.0 allows to exploit an XSS through an unrestricted file upload, together with a bad entropy of filenames. With this an attacker can upload a malicious HTML file, then guess the filename of the uploaded file and send it to a potential victim.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fwg4-q55q-w62p",
"modified": "2024-06-07T15:30:34Z",
"modified": "2025-05-19T15:30:29Z",
"published": "2023-11-21T00:30:27Z",
"aliases": [
"CVE-2023-6199"
],
"details": "Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.\n",
"details": "Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-372v-gvcg-hfrh",
"modified": "2023-12-27T18:30:20Z",
"modified": "2025-05-19T15:30:29Z",
"published": "2023-12-20T18:30:33Z",
"aliases": [
"CVE-2023-49269"
],
"details": "Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'adults' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.\n\n",
"details": "Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'adults' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4827-2m3r-j4qh",
"modified": "2024-01-02T15:30:24Z",
"modified": "2025-05-19T15:30:31Z",
"published": "2023-12-21T18:30:23Z",
"aliases": [
"CVE-2023-45119"
],
"details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'n' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n",
"details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'n' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9g9h-7mhh-5mcr",
"modified": "2023-12-27T00:30:25Z",
"modified": "2025-05-19T15:30:30Z",
"published": "2023-12-20T21:30:35Z",
"aliases": [
"CVE-2023-49271"
],
"details": "Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_out_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.\n\n",
"details": "Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_out_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9pmm-p2wc-hfx4",
"modified": "2024-01-02T15:30:24Z",
"modified": "2025-05-19T15:30:31Z",
"published": "2023-12-21T18:30:23Z",
"aliases": [
"CVE-2023-45120"
],
"details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'qid' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n",
"details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'qid' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j4xm-8c7j-fjwj",
"modified": "2024-01-02T15:30:24Z",
"modified": "2025-05-19T15:30:30Z",
"published": "2023-12-21T18:30:22Z",
"aliases": [
"CVE-2023-45115"
],
"details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'ch' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n",
"details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'ch' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j6r8-x8pp-9mcq",
"modified": "2024-02-01T18:31:07Z",
"modified": "2025-05-19T15:30:30Z",
"published": "2023-12-20T21:30:35Z",
"aliases": [
"CVE-2023-49272"
],
"details": "Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'children' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.\n\n",
"details": "Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'children' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jxpp-2jgf-79rr",
"modified": "2024-01-02T15:30:24Z",
"modified": "2025-05-19T15:30:31Z",
"published": "2023-12-21T18:30:22Z",
"aliases": [
"CVE-2023-45118"
],
"details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'fdid' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n",
"details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'fdid' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ppqr-xhhp-8qc5",
"modified": "2023-12-27T00:30:25Z",
"modified": "2025-05-19T15:30:30Z",
"published": "2023-12-20T21:30:35Z",
"aliases": [
"CVE-2023-49270"
],
"details": "Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_in_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.\n\n",
"details": "Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_in_date' parameter of the reservation.php resource is copied into the HTML document as plain text between tags. Any input is echoed unmodified in the application's response.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qjw8-8m2x-jvh6",
"modified": "2024-01-02T15:30:24Z",
"modified": "2025-05-19T15:30:30Z",
"published": "2023-12-21T18:30:22Z",
"aliases": [
"CVE-2023-45117"
],
"details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'eid' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n",
"details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'eid' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vg76-xrj2-3p56",
"modified": "2024-01-02T15:30:24Z",
"modified": "2025-05-19T15:30:31Z",
"published": "2023-12-21T18:30:23Z",
"aliases": [
"CVE-2023-45121"
],
"details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'desc' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n",
"details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'desc' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xqm8-jv67-vcvj",
"modified": "2024-01-02T15:30:24Z",
"modified": "2025-05-19T15:30:30Z",
"published": "2023-12-21T18:30:22Z",
"aliases": [
"CVE-2023-45116"
],
"details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'demail' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n",
"details": "Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'demail' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.",
"severity": [
{
"type": "CVSS_V3",
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-352"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v5gh-4369-4w97",
"modified": "2024-04-08T06:31:30Z",
"modified": "2025-05-19T15:30:31Z",
"published": "2024-04-08T06:31:30Z",
"aliases": [
"CVE-2024-1956"
],
"details": "The wpb-show-core WordPress plugin before 2.7 does not sanitise and escape the parameters before outputting it back in the response of an unauthenticated request, leading to a Reflected Cross-Site Scripting",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-08T05:15:07Z"
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,

Some files were not shown because too many files have changed in this diff Show More