From fc6ff4686a70072cdaff6169c44b3f30665df232 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 29 Nov 2024 03:32:39 +0000 Subject: [PATCH] Publish Advisories GHSA-4gc8-mmm3-6xff GHSA-4q2m-qgp3-g9h6 GHSA-cfw8-hh97-639v GHSA-f4q4-prrr-6rxf GHSA-gq9r-ppv5-vm43 GHSA-grq9-8qm8-vhjr GHSA-rcvr-m4pw-53h5 --- .../GHSA-4gc8-mmm3-6xff.json | 40 +++++++++++++ .../GHSA-4q2m-qgp3-g9h6.json | 56 +++++++++++++++++++ .../GHSA-cfw8-hh97-639v.json | 40 +++++++++++++ .../GHSA-f4q4-prrr-6rxf.json | 40 +++++++++++++ .../GHSA-gq9r-ppv5-vm43.json | 40 +++++++++++++ .../GHSA-grq9-8qm8-vhjr.json | 40 +++++++++++++ .../GHSA-rcvr-m4pw-53h5.json | 52 +++++++++++++++++ 7 files changed, 308 insertions(+) create mode 100644 advisories/unreviewed/2024/11/GHSA-4gc8-mmm3-6xff/GHSA-4gc8-mmm3-6xff.json create mode 100644 advisories/unreviewed/2024/11/GHSA-4q2m-qgp3-g9h6/GHSA-4q2m-qgp3-g9h6.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cfw8-hh97-639v/GHSA-cfw8-hh97-639v.json create mode 100644 advisories/unreviewed/2024/11/GHSA-f4q4-prrr-6rxf/GHSA-f4q4-prrr-6rxf.json create mode 100644 advisories/unreviewed/2024/11/GHSA-gq9r-ppv5-vm43/GHSA-gq9r-ppv5-vm43.json create mode 100644 advisories/unreviewed/2024/11/GHSA-grq9-8qm8-vhjr/GHSA-grq9-8qm8-vhjr.json create mode 100644 advisories/unreviewed/2024/11/GHSA-rcvr-m4pw-53h5/GHSA-rcvr-m4pw-53h5.json diff --git a/advisories/unreviewed/2024/11/GHSA-4gc8-mmm3-6xff/GHSA-4gc8-mmm3-6xff.json b/advisories/unreviewed/2024/11/GHSA-4gc8-mmm3-6xff/GHSA-4gc8-mmm3-6xff.json new file mode 100644 index 00000000000..aa49d2fed52 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4gc8-mmm3-6xff/GHSA-4gc8-mmm3-6xff.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gc8-mmm3-6xff", + "modified": "2024-11-29T03:31:04Z", + "published": "2024-11-29T03:31:04Z", + "aliases": [ + "CVE-2024-8299" + ], + "details": "Uncontrolled Search Path Element vulnerability in ICONICS GENESIS64 all versions, Mitsubishi Electric GENESIS64 all versions and Mitsubishi Electric MC Works64 all versions allows a local authenticated attacker to execute a malicious code by storing a specially crafted DLL in a specific folder. This could lead to disclose, tamper with, destroy, or delete information in the affected products, or cause a denial of service (DoS) condition on the products.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8299" + }, + { + "type": "WEB", + "url": "https://jvn.jp/vu/JVNVU93891820" + }, + { + "type": "WEB", + "url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-010_en.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T23:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4q2m-qgp3-g9h6/GHSA-4q2m-qgp3-g9h6.json b/advisories/unreviewed/2024/11/GHSA-4q2m-qgp3-g9h6/GHSA-4q2m-qgp3-g9h6.json new file mode 100644 index 00000000000..7ae59e7aa73 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4q2m-qgp3-g9h6/GHSA-4q2m-qgp3-g9h6.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4q2m-qgp3-g9h6", + "modified": "2024-11-29T03:31:04Z", + "published": "2024-11-29T03:31:04Z", + "aliases": [ + "CVE-2024-11970" + ], + "details": "A vulnerability classified as critical has been found in code-projects Concert Ticket Ordering System 1.0. Affected is an unknown function of the file /tour(cor).php. The manipulation of the argument mai leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11970" + }, + { + "type": "WEB", + "url": "https://github.com/halhalz/1/issues/1" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.286380" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.286380" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.453376" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cfw8-hh97-639v/GHSA-cfw8-hh97-639v.json b/advisories/unreviewed/2024/11/GHSA-cfw8-hh97-639v/GHSA-cfw8-hh97-639v.json new file mode 100644 index 00000000000..3058e92a78b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cfw8-hh97-639v/GHSA-cfw8-hh97-639v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfw8-hh97-639v", + "modified": "2024-11-29T03:31:04Z", + "published": "2024-11-29T03:31:04Z", + "aliases": [ + "CVE-2024-11978" + ], + "details": "DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11978" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-8270-a56e6-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-8269-22a8f-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T03:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-f4q4-prrr-6rxf/GHSA-f4q4-prrr-6rxf.json b/advisories/unreviewed/2024/11/GHSA-f4q4-prrr-6rxf/GHSA-f4q4-prrr-6rxf.json new file mode 100644 index 00000000000..935cc21b945 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-f4q4-prrr-6rxf/GHSA-f4q4-prrr-6rxf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4q4-prrr-6rxf", + "modified": "2024-11-29T03:31:04Z", + "published": "2024-11-29T03:31:04Z", + "aliases": [ + "CVE-2024-11979" + ], + "details": "DreamMaker from Interinfo has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11979" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-8272-13a13-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-8271-29871-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-29T03:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gq9r-ppv5-vm43/GHSA-gq9r-ppv5-vm43.json b/advisories/unreviewed/2024/11/GHSA-gq9r-ppv5-vm43/GHSA-gq9r-ppv5-vm43.json new file mode 100644 index 00000000000..5c36977de19 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gq9r-ppv5-vm43/GHSA-gq9r-ppv5-vm43.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq9r-ppv5-vm43", + "modified": "2024-11-29T03:31:04Z", + "published": "2024-11-29T03:31:04Z", + "aliases": [ + "CVE-2024-8300" + ], + "details": "Dead Code vulnerability in ICONICS GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3 and Mitsubishi Electric GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3 allows a local authenticated attacker to execute a malicious code by tampering with a specially crafted DLL. This could lead to disclose, tamper with, destroy, or delete information in the affected products, or cause a denial of service (DoS) condition on the products.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8300" + }, + { + "type": "WEB", + "url": "https://jvn.jp/vu/JVNVU93891820" + }, + { + "type": "WEB", + "url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-010_en.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-561" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T23:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-grq9-8qm8-vhjr/GHSA-grq9-8qm8-vhjr.json b/advisories/unreviewed/2024/11/GHSA-grq9-8qm8-vhjr/GHSA-grq9-8qm8-vhjr.json new file mode 100644 index 00000000000..d19f6d0d778 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-grq9-8qm8-vhjr/GHSA-grq9-8qm8-vhjr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grq9-8qm8-vhjr", + "modified": "2024-11-29T03:31:04Z", + "published": "2024-11-29T03:31:04Z", + "aliases": [ + "CVE-2024-9852" + ], + "details": "Uncontrolled Search Path Element vulnerability in ICONICS GENESIS64 all versions, Mitsubishi Electric GENESIS64 all versions and Mitsubishi Electric MC Works64 all versions allows a local authenticated attacker to execute a malicious code by storing a specially crafted DLL in a specific folder. This could lead to disclose, tamper with, destroy, or delete information in the affected products, or cause a denial of service (DoS) condition on the products.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9852" + }, + { + "type": "WEB", + "url": "https://jvn.jp/vu/JVNVU93891820" + }, + { + "type": "WEB", + "url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-010_en.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T23:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-rcvr-m4pw-53h5/GHSA-rcvr-m4pw-53h5.json b/advisories/unreviewed/2024/11/GHSA-rcvr-m4pw-53h5/GHSA-rcvr-m4pw-53h5.json new file mode 100644 index 00000000000..85c730c0fa8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-rcvr-m4pw-53h5/GHSA-rcvr-m4pw-53h5.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcvr-m4pw-53h5", + "modified": "2024-11-29T03:31:04Z", + "published": "2024-11-29T03:31:04Z", + "aliases": [ + "CVE-2024-11971" + ], + "details": "A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerability is an unknown functionality of the file /commons/attachment/upload of the component Avatar Handler. The manipulation of the argument files leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11971" + }, + { + "type": "WEB", + "url": "https://github.com/dycccccccc/jpress/blob/main/JPRESS%20file%20upload%20leads%20to%20code%20execution.docx" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.286381" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.286381" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.453637" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-28T22:15:15Z" + } +} \ No newline at end of file