Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2023-12-21 15:31:50 +00:00
parent 29a6ce5afa
commit fdefd11eec
39 changed files with 1115 additions and 14 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m3qw-f5f6-m6r3",
"modified": "2023-06-13T18:30:39Z",
"modified": "2023-12-21T15:30:31Z",
"published": "2023-06-13T18:30:39Z",
"aliases": [
"CVE-2023-31438"
],
"details": "An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [
@@ -18,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31438"
},
{
"type": "WEB",
"url": "https://github.com/systemd/systemd/pull/28886"
},
{
"type": "WEB",
"url": "https://github.com/kastel-security/Journald"
@@ -33,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-354"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-06-13T17:15:14Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mvwm-rcrw-pr2j",
"modified": "2023-06-13T18:30:39Z",
"modified": "2023-12-21T15:30:31Z",
"published": "2023-06-13T18:30:39Z",
"aliases": [
"CVE-2023-31439"
],
"details": "An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [
@@ -18,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31439"
},
{
"type": "WEB",
"url": "https://github.com/systemd/systemd/pull/28885"
},
{
"type": "WEB",
"url": "https://github.com/kastel-security/Journald"
@@ -33,9 +40,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-354"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-06-13T17:15:14Z"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "http://packetstormsecurity.com/files/175397/VinChin-VMWare-Backup-7.0-Hardcoded-Credential-Remote-Code-Execution.html"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/176289/Vinchin-Backup-And-Recovery-Command-Injection.html"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2023/Oct/31"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "http://packetstormsecurity.com/files/175397/VinChin-VMWare-Backup-7.0-Hardcoded-Credential-Remote-Code-Execution.html"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/176289/Vinchin-Backup-And-Recovery-Command-Injection.html"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2023/Oct/31"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m77w-6vjw-wh2f",
"modified": "2023-10-03T18:30:23Z",
"modified": "2023-12-21T15:30:31Z",
"published": "2023-10-03T18:30:23Z",
"aliases": [
"CVE-2023-4911"
@@ -81,6 +81,10 @@
"type": "WEB",
"url": "http://packetstormsecurity.com/files/174986/glibc-ld.so-Local-Privilege-Escalation.html"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/176288/Glibc-Tunables-Privilege-Escalation.html"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2023/Oct/11"
@@ -116,9 +120,10 @@
],
"database_specific": {
"cwe_ids": [
"CWE-122",
"CWE-787"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-03T18:15:10Z"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-29rj-6gfr-wmfc",
"modified": "2023-12-21T15:30:32Z",
"published": "2023-12-21T15:30:32Z",
"aliases": [
"CVE-2023-50823"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wipeout Media CSS & JavaScript Toolbox allows Stored XSS.This issue affects CSS & JavaScript Toolbox: from n/a through 11.7.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50823"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/css-javascript-toolbox/wordpress-css-javascript-toolbox-plugin-11-7-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-21T15:15:11Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-427f-qf2r-ffq3",
"modified": "2023-12-21T15:30:32Z",
"published": "2023-12-21T15:30:32Z",
"aliases": [
"CVE-2023-6122"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in İstanbul Soft Informatics and Consultancy Limited Company Softomi Gelişmiş C2C Pazaryeri Yazılımı allows Reflected XSS.This issue affects Softomi Gelişmiş C2C Pazaryeri Yazılımı: before 12122023.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6122"
},
{
"type": "WEB",
"url": "https://www.usom.gov.tr/bildirim/tr-23-0724"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-21T14:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4r95-c6hr-v2wx",
"modified": "2023-12-21T15:30:32Z",
"published": "2023-12-21T15:30:32Z",
"aliases": [
"CVE-2023-49162"
],
"details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BigCommerce BigCommerce For WordPress.This issue affects BigCommerce For WordPress: from n/a through 5.0.6.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49162"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/bigcommerce/wordpress-bigcommerce-for-wordpress-plugin-5-0-6-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-21T14:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-53j2-c3fp-6vh7",
"modified": "2023-12-21T15:30:32Z",
"published": "2023-12-21T15:30:32Z",
"aliases": [
"CVE-2023-50825"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terrier Tenacity iframe Shortcode allows Stored XSS.This issue affects iframe Shortcode: from n/a through 2.0.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50825"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/iframe-shortcode/wordpress-iframe-shortcode-plugin-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-21T15:15:11Z"
}
}
@@ -25,6 +25,10 @@
{
"type": "WEB",
"url": "https://lists.apache.org/thread/rs7cr3yp726mb89s1m844hy9pq7frgcn"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/12/21/4"
}
],
"database_specific": {
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-62hv-fgc6-fxm4",
"modified": "2023-12-21T15:30:32Z",
"published": "2023-12-21T15:30:32Z",
"aliases": [
"CVE-2023-50824"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Batt Insert or Embed Articulate Content into WordPress allows Stored XSS.This issue affects Insert or Embed Articulate Content into WordPress: from n/a through 4.3000000021.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50824"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/insert-or-embed-articulate-content-into-wordpress/wordpress-insert-or-embed-articulate-content-into-wordpress-plugin-4-3000000021-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-21T15:15:11Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6gj8-gj3v-ccw7",
"modified": "2023-12-21T15:30:32Z",
"published": "2023-12-21T15:30:32Z",
"aliases": [
"CVE-2023-48116"
],
"details": "SmarterTools SmarterMail 16.x 8495 through 8664 before 8747 allows stored XSS via a crafted description of a Calendar appointment.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48116"
},
{
"type": "WEB",
"url": "https://co3us.gitbook.io/write-ups/stored-xss-in-calendar-component-of-smartermail-cve-2023-48116"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-21T15:15:09Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6m9r-7wrx-xmr6",
"modified": "2023-12-21T12:30:28Z",
"modified": "2023-12-21T15:30:31Z",
"published": "2023-12-21T12:30:28Z",
"aliases": [
"CVE-2023-49920"
@@ -25,6 +25,10 @@
{
"type": "WEB",
"url": "https://lists.apache.org/thread/mnwd2vcfw3gms6ft6kl951vfbqrxsnjq"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/12/21/3"
}
],
"database_specific": {
@@ -32,7 +32,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200"
"CWE-200",
"CWE-401"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -0,0 +1,46 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7j9h-ch38-474r",
"modified": "2023-12-21T15:30:33Z",
"published": "2023-12-21T15:30:33Z",
"aliases": [
"CVE-2023-7035"
],
"details": "A vulnerability was found in automad up to 1.10.9 and classified as problematic. Affected by this issue is some unknown functionality of the file packages\\standard\\templates\\post.php of the component Setting Handler. The manipulation of the argument sitename leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-248684. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7035"
},
{
"type": "WEB",
"url": "https://github.com/screetsec/VDD/tree/main/Automad%20CMS/Stored%20Cross%20Site%20Scripting%20(XSS)"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.248684"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.248684"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-21T15:15:13Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7pcg-c7pp-5c42",
"modified": "2023-12-21T15:30:32Z",
"published": "2023-12-21T15:30:32Z",
"aliases": [
"CVE-2022-45377"
],
"details": "Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload for WooCommerce.This issue affects Drag and Drop Multiple File Upload for WooCommerce: from n/a through 1.0.8.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45377"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/drag-and-drop-multiple-file-upload-for-woocommerce/wordpress-drag-and-drop-multiple-file-upload-for-woocommerce-plugin-1-0-8-multiple-vulnerabilities?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-21T13:15:08Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7xwg-hh9r-4gjx",
"modified": "2023-12-21T15:30:32Z",
"published": "2023-12-21T15:30:32Z",
"aliases": [
"CVE-2023-50828"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Vongries Ultimate Dashboard Custom WordPress Dashboard allows Stored XSS.This issue affects Ultimate Dashboard Custom WordPress Dashboard: from n/a through 3.7.11.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50828"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/ultimate-dashboard/wordpress-ultimate-dashboard-plugin-3-7-11-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-21T15:15:12Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8f57-wcmg-4jmh",
"modified": "2023-12-21T12:30:27Z",
"modified": "2023-12-21T15:30:31Z",
"published": "2023-12-21T12:30:27Z",
"aliases": [
"CVE-2023-48291"
@@ -25,6 +25,10 @@
{
"type": "WEB",
"url": "https://lists.apache.org/thread/3nl0h014274yjlt1hd02z0q78ftyz0z3"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/12/21/1"
}
],
"database_specific": {
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8qwh-2gcf-fj4g",
"modified": "2023-12-21T15:30:32Z",
"published": "2023-12-21T15:30:32Z",
"aliases": [
"CVE-2023-6145"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in İstanbul Soft Informatics and Consultancy Limited Company Softomi Advanced C2C Marketplace Software allows SQL Injection.This issue affects Softomi Advanced C2C Marketplace Software: before 12122023.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6145"
},
{
"type": "WEB",
"url": "https://www.usom.gov.tr/bildirim/tr-23-0724"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-21T14:15:09Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8rvj-w5g5-prc2",
"modified": "2023-12-21T15:30:32Z",
"published": "2023-12-21T15:30:32Z",
"aliases": [
"CVE-2023-32242"
],
"details": "Deserialization of Untrusted Data vulnerability in xtemos WoodMart - Multipurpose WooCommerce Theme.This issue affects WoodMart - Multipurpose WooCommerce Theme: from n/a through 1.0.36.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32242"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/woodmart-core/wordpress-woodmart-core-plugin-1-0-36-php-object-injection?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-21T13:15:08Z"
}
}

Some files were not shown because too many files have changed in this diff Show More