Publish Advisories

GHSA-28gh-p4vv-27p2
GHSA-5rxh-xq99-fg3p
GHSA-8v94-3gmx-4pmj
This commit is contained in:
advisory-database[bot]
2024-11-03 12:32:44 +00:00
parent 92f459bda8
commit fbc28263a8
3 changed files with 166 additions and 0 deletions
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-28gh-p4vv-27p2",
"modified": "2024-11-03T12:30:48Z",
"published": "2024-11-03T12:30:47Z",
"aliases": [
"CVE-2024-10732"
],
"details": "A vulnerability has been found in Tongda OA 2017 up to 11.10 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /module/word_model/view/index.php. The manipulation of the argument query_str leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10732"
},
{
"type": "WEB",
"url": "https://github.com/LvZCh/td/issues/17"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.282901"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.282901"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.433532"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-03T11:15:03Z"
}
}
@@ -0,0 +1,54 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5rxh-xq99-fg3p",
"modified": "2024-11-03T12:30:48Z",
"published": "2024-11-03T12:30:48Z",
"aliases": [
"CVE-2024-10731"
],
"details": "A vulnerability, which was classified as critical, was found in Tongda OA up to 11.10. Affected is an unknown function of the file /pda/appcenter/check_seal.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10731"
},
{
"type": "WEB",
"url": "https://github.com/LvZCh/td/issues/16"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.282900"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.282900"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.433531"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-03T10:15:03Z"
}
}
@@ -0,0 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8v94-3gmx-4pmj",
"modified": "2024-11-03T12:30:48Z",
"published": "2024-11-03T12:30:48Z",
"aliases": [
"CVE-2024-10733"
],
"details": "A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument uid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10733"
},
{
"type": "WEB",
"url": "https://github.com/415Curry/cve/issues/1"
},
{
"type": "WEB",
"url": "https://code-projects.org"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.282902"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.282902"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.435235"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-03T12:15:12Z"
}
}