From fdefd11eec42fab6d39472c3cc6ce535a1c8fbf4 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 21 Dec 2023 15:31:50 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-m3qw-f5f6-m6r3.json | 15 ++++-- .../GHSA-mvwm-rcrw-pr2j.json | 15 ++++-- .../GHSA-565x-m8jw-g2f2.json | 4 ++ .../GHSA-gj84-56mj-c85j.json | 4 ++ .../GHSA-m77w-6vjw-wh2f.json | 9 +++- .../GHSA-29rj-6gfr-wmfc.json | 38 +++++++++++++++ .../GHSA-427f-qf2r-ffq3.json | 38 +++++++++++++++ .../GHSA-4r95-c6hr-v2wx.json | 38 +++++++++++++++ .../GHSA-53j2-c3fp-6vh7.json | 38 +++++++++++++++ .../GHSA-5938-79hg-xh3q.json | 4 ++ .../GHSA-62hv-fgc6-fxm4.json | 38 +++++++++++++++ .../GHSA-6gj8-gj3v-ccw7.json | 35 ++++++++++++++ .../GHSA-6m9r-7wrx-xmr6.json | 6 ++- .../GHSA-6ww3-v82p-jv78.json | 3 +- .../GHSA-7j9h-ch38-474r.json | 46 +++++++++++++++++++ .../GHSA-7pcg-c7pp-5c42.json | 38 +++++++++++++++ .../GHSA-7xwg-hh9r-4gjx.json | 38 +++++++++++++++ .../GHSA-8f57-wcmg-4jmh.json | 6 ++- .../GHSA-8qwh-2gcf-fj4g.json | 38 +++++++++++++++ .../GHSA-8rvj-w5g5-prc2.json | 38 +++++++++++++++ .../GHSA-c82j-mm7v-vfp8.json | 38 +++++++++++++++ .../GHSA-f23h-52hj-99p6.json | 4 ++ .../GHSA-f7j7-68hw-w26q.json | 38 +++++++++++++++ .../GHSA-gxvx-vq8h-p56h.json | 38 +++++++++++++++ .../GHSA-hf9h-c8cv-r62j.json | 38 +++++++++++++++ .../GHSA-j28j-v2qr-58x6.json | 38 +++++++++++++++ .../GHSA-jc8g-9q2p-m8vx.json | 38 +++++++++++++++ .../GHSA-jfg8-q228-h5m4.json | 38 +++++++++++++++ .../GHSA-m4r9-8h98-x643.json | 38 +++++++++++++++ .../GHSA-m9vp-5pvm-gxw4.json | 38 +++++++++++++++ .../GHSA-mfr4-4gq8-693m.json | 35 ++++++++++++++ .../GHSA-pxch-wr7m-rwxj.json | 6 ++- .../GHSA-q6xr-235v-39cm.json | 31 +++++++++++++ .../GHSA-qmhv-fq76-x3j5.json | 35 ++++++++++++++ .../GHSA-rjjc-gg9m-vhv8.json | 35 ++++++++++++++ .../GHSA-rw43-gq3v-mchp.json | 38 +++++++++++++++ .../GHSA-v968-6pmm-9qc5.json | 38 +++++++++++++++ .../GHSA-wrq3-v46f-59mp.json | 38 +++++++++++++++ .../GHSA-x4h7-65jv-x57h.json | 38 +++++++++++++++ 39 files changed, 1115 insertions(+), 14 deletions(-) create mode 100644 advisories/unreviewed/2023/12/GHSA-29rj-6gfr-wmfc/GHSA-29rj-6gfr-wmfc.json create mode 100644 advisories/unreviewed/2023/12/GHSA-427f-qf2r-ffq3/GHSA-427f-qf2r-ffq3.json create mode 100644 advisories/unreviewed/2023/12/GHSA-4r95-c6hr-v2wx/GHSA-4r95-c6hr-v2wx.json create mode 100644 advisories/unreviewed/2023/12/GHSA-53j2-c3fp-6vh7/GHSA-53j2-c3fp-6vh7.json create mode 100644 advisories/unreviewed/2023/12/GHSA-62hv-fgc6-fxm4/GHSA-62hv-fgc6-fxm4.json create mode 100644 advisories/unreviewed/2023/12/GHSA-6gj8-gj3v-ccw7/GHSA-6gj8-gj3v-ccw7.json create mode 100644 advisories/unreviewed/2023/12/GHSA-7j9h-ch38-474r/GHSA-7j9h-ch38-474r.json create mode 100644 advisories/unreviewed/2023/12/GHSA-7pcg-c7pp-5c42/GHSA-7pcg-c7pp-5c42.json create mode 100644 advisories/unreviewed/2023/12/GHSA-7xwg-hh9r-4gjx/GHSA-7xwg-hh9r-4gjx.json create mode 100644 advisories/unreviewed/2023/12/GHSA-8qwh-2gcf-fj4g/GHSA-8qwh-2gcf-fj4g.json create mode 100644 advisories/unreviewed/2023/12/GHSA-8rvj-w5g5-prc2/GHSA-8rvj-w5g5-prc2.json create mode 100644 advisories/unreviewed/2023/12/GHSA-c82j-mm7v-vfp8/GHSA-c82j-mm7v-vfp8.json create mode 100644 advisories/unreviewed/2023/12/GHSA-f7j7-68hw-w26q/GHSA-f7j7-68hw-w26q.json create mode 100644 advisories/unreviewed/2023/12/GHSA-gxvx-vq8h-p56h/GHSA-gxvx-vq8h-p56h.json create mode 100644 advisories/unreviewed/2023/12/GHSA-hf9h-c8cv-r62j/GHSA-hf9h-c8cv-r62j.json create mode 100644 advisories/unreviewed/2023/12/GHSA-j28j-v2qr-58x6/GHSA-j28j-v2qr-58x6.json create mode 100644 advisories/unreviewed/2023/12/GHSA-jc8g-9q2p-m8vx/GHSA-jc8g-9q2p-m8vx.json create mode 100644 advisories/unreviewed/2023/12/GHSA-jfg8-q228-h5m4/GHSA-jfg8-q228-h5m4.json create mode 100644 advisories/unreviewed/2023/12/GHSA-m4r9-8h98-x643/GHSA-m4r9-8h98-x643.json create mode 100644 advisories/unreviewed/2023/12/GHSA-m9vp-5pvm-gxw4/GHSA-m9vp-5pvm-gxw4.json create mode 100644 advisories/unreviewed/2023/12/GHSA-mfr4-4gq8-693m/GHSA-mfr4-4gq8-693m.json create mode 100644 advisories/unreviewed/2023/12/GHSA-q6xr-235v-39cm/GHSA-q6xr-235v-39cm.json create mode 100644 advisories/unreviewed/2023/12/GHSA-qmhv-fq76-x3j5/GHSA-qmhv-fq76-x3j5.json create mode 100644 advisories/unreviewed/2023/12/GHSA-rjjc-gg9m-vhv8/GHSA-rjjc-gg9m-vhv8.json create mode 100644 advisories/unreviewed/2023/12/GHSA-rw43-gq3v-mchp/GHSA-rw43-gq3v-mchp.json create mode 100644 advisories/unreviewed/2023/12/GHSA-v968-6pmm-9qc5/GHSA-v968-6pmm-9qc5.json create mode 100644 advisories/unreviewed/2023/12/GHSA-wrq3-v46f-59mp/GHSA-wrq3-v46f-59mp.json create mode 100644 advisories/unreviewed/2023/12/GHSA-x4h7-65jv-x57h/GHSA-x4h7-65jv-x57h.json diff --git a/advisories/unreviewed/2023/06/GHSA-m3qw-f5f6-m6r3/GHSA-m3qw-f5f6-m6r3.json b/advisories/unreviewed/2023/06/GHSA-m3qw-f5f6-m6r3/GHSA-m3qw-f5f6-m6r3.json index 84d6ac9946e..27d289c6c0d 100644 --- a/advisories/unreviewed/2023/06/GHSA-m3qw-f5f6-m6r3/GHSA-m3qw-f5f6-m6r3.json +++ b/advisories/unreviewed/2023/06/GHSA-m3qw-f5f6-m6r3/GHSA-m3qw-f5f6-m6r3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m3qw-f5f6-m6r3", - "modified": "2023-06-13T18:30:39Z", + "modified": "2023-12-21T15:30:31Z", "published": "2023-06-13T18:30:39Z", "aliases": [ "CVE-2023-31438" ], "details": "An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -18,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31438" }, + { + "type": "WEB", + "url": "https://github.com/systemd/systemd/pull/28886" + }, { "type": "WEB", "url": "https://github.com/kastel-security/Journald" @@ -33,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-354" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-06-13T17:15:14Z" diff --git a/advisories/unreviewed/2023/06/GHSA-mvwm-rcrw-pr2j/GHSA-mvwm-rcrw-pr2j.json b/advisories/unreviewed/2023/06/GHSA-mvwm-rcrw-pr2j/GHSA-mvwm-rcrw-pr2j.json index d37ac077854..c9b781c49fa 100644 --- a/advisories/unreviewed/2023/06/GHSA-mvwm-rcrw-pr2j/GHSA-mvwm-rcrw-pr2j.json +++ b/advisories/unreviewed/2023/06/GHSA-mvwm-rcrw-pr2j/GHSA-mvwm-rcrw-pr2j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mvwm-rcrw-pr2j", - "modified": "2023-06-13T18:30:39Z", + "modified": "2023-12-21T15:30:31Z", "published": "2023-06-13T18:30:39Z", "aliases": [ "CVE-2023-31439" ], "details": "An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -18,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31439" }, + { + "type": "WEB", + "url": "https://github.com/systemd/systemd/pull/28885" + }, { "type": "WEB", "url": "https://github.com/kastel-security/Journald" @@ -33,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-354" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-06-13T17:15:14Z" diff --git a/advisories/unreviewed/2023/10/GHSA-565x-m8jw-g2f2/GHSA-565x-m8jw-g2f2.json b/advisories/unreviewed/2023/10/GHSA-565x-m8jw-g2f2/GHSA-565x-m8jw-g2f2.json index 5be04425b35..4a193375e0e 100644 --- a/advisories/unreviewed/2023/10/GHSA-565x-m8jw-g2f2/GHSA-565x-m8jw-g2f2.json +++ b/advisories/unreviewed/2023/10/GHSA-565x-m8jw-g2f2/GHSA-565x-m8jw-g2f2.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "http://packetstormsecurity.com/files/175397/VinChin-VMWare-Backup-7.0-Hardcoded-Credential-Remote-Code-Execution.html" }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176289/Vinchin-Backup-And-Recovery-Command-Injection.html" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2023/Oct/31" diff --git a/advisories/unreviewed/2023/10/GHSA-gj84-56mj-c85j/GHSA-gj84-56mj-c85j.json b/advisories/unreviewed/2023/10/GHSA-gj84-56mj-c85j/GHSA-gj84-56mj-c85j.json index ca565c5cc74..378831ae07e 100644 --- a/advisories/unreviewed/2023/10/GHSA-gj84-56mj-c85j/GHSA-gj84-56mj-c85j.json +++ b/advisories/unreviewed/2023/10/GHSA-gj84-56mj-c85j/GHSA-gj84-56mj-c85j.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "http://packetstormsecurity.com/files/175397/VinChin-VMWare-Backup-7.0-Hardcoded-Credential-Remote-Code-Execution.html" }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176289/Vinchin-Backup-And-Recovery-Command-Injection.html" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2023/Oct/31" diff --git a/advisories/unreviewed/2023/10/GHSA-m77w-6vjw-wh2f/GHSA-m77w-6vjw-wh2f.json b/advisories/unreviewed/2023/10/GHSA-m77w-6vjw-wh2f/GHSA-m77w-6vjw-wh2f.json index 2a4ba12a5c6..2a526bbd1ef 100644 --- a/advisories/unreviewed/2023/10/GHSA-m77w-6vjw-wh2f/GHSA-m77w-6vjw-wh2f.json +++ b/advisories/unreviewed/2023/10/GHSA-m77w-6vjw-wh2f/GHSA-m77w-6vjw-wh2f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m77w-6vjw-wh2f", - "modified": "2023-10-03T18:30:23Z", + "modified": "2023-12-21T15:30:31Z", "published": "2023-10-03T18:30:23Z", "aliases": [ "CVE-2023-4911" @@ -81,6 +81,10 @@ "type": "WEB", "url": "http://packetstormsecurity.com/files/174986/glibc-ld.so-Local-Privilege-Escalation.html" }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176288/Glibc-Tunables-Privilege-Escalation.html" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2023/Oct/11" @@ -116,9 +120,10 @@ ], "database_specific": { "cwe_ids": [ + "CWE-122", "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-03T18:15:10Z" diff --git a/advisories/unreviewed/2023/12/GHSA-29rj-6gfr-wmfc/GHSA-29rj-6gfr-wmfc.json b/advisories/unreviewed/2023/12/GHSA-29rj-6gfr-wmfc/GHSA-29rj-6gfr-wmfc.json new file mode 100644 index 00000000000..8d96bea0db2 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-29rj-6gfr-wmfc/GHSA-29rj-6gfr-wmfc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29rj-6gfr-wmfc", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-50823" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wipeout Media CSS & JavaScript Toolbox allows Stored XSS.This issue affects CSS & JavaScript Toolbox: from n/a through 11.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50823" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/css-javascript-toolbox/wordpress-css-javascript-toolbox-plugin-11-7-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-427f-qf2r-ffq3/GHSA-427f-qf2r-ffq3.json b/advisories/unreviewed/2023/12/GHSA-427f-qf2r-ffq3/GHSA-427f-qf2r-ffq3.json new file mode 100644 index 00000000000..f56bc42f597 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-427f-qf2r-ffq3/GHSA-427f-qf2r-ffq3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-427f-qf2r-ffq3", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-6122" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in İstanbul Soft Informatics and Consultancy Limited Company Softomi Gelişmiş C2C Pazaryeri Yazılımı allows Reflected XSS.This issue affects Softomi Gelişmiş C2C Pazaryeri Yazılımı: before 12122023.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6122" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-23-0724" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-4r95-c6hr-v2wx/GHSA-4r95-c6hr-v2wx.json b/advisories/unreviewed/2023/12/GHSA-4r95-c6hr-v2wx/GHSA-4r95-c6hr-v2wx.json new file mode 100644 index 00000000000..dd00a8e66ff --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-4r95-c6hr-v2wx/GHSA-4r95-c6hr-v2wx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r95-c6hr-v2wx", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-49162" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BigCommerce BigCommerce For WordPress.This issue affects BigCommerce For WordPress: from n/a through 5.0.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49162" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/bigcommerce/wordpress-bigcommerce-for-wordpress-plugin-5-0-6-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-53j2-c3fp-6vh7/GHSA-53j2-c3fp-6vh7.json b/advisories/unreviewed/2023/12/GHSA-53j2-c3fp-6vh7/GHSA-53j2-c3fp-6vh7.json new file mode 100644 index 00000000000..d467afe8875 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-53j2-c3fp-6vh7/GHSA-53j2-c3fp-6vh7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53j2-c3fp-6vh7", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-50825" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terrier Tenacity iframe Shortcode allows Stored XSS.This issue affects iframe Shortcode: from n/a through 2.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50825" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/iframe-shortcode/wordpress-iframe-shortcode-plugin-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-5938-79hg-xh3q/GHSA-5938-79hg-xh3q.json b/advisories/unreviewed/2023/12/GHSA-5938-79hg-xh3q/GHSA-5938-79hg-xh3q.json index 51194888091..d46ecb781fe 100644 --- a/advisories/unreviewed/2023/12/GHSA-5938-79hg-xh3q/GHSA-5938-79hg-xh3q.json +++ b/advisories/unreviewed/2023/12/GHSA-5938-79hg-xh3q/GHSA-5938-79hg-xh3q.json @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/rs7cr3yp726mb89s1m844hy9pq7frgcn" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/12/21/4" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-62hv-fgc6-fxm4/GHSA-62hv-fgc6-fxm4.json b/advisories/unreviewed/2023/12/GHSA-62hv-fgc6-fxm4/GHSA-62hv-fgc6-fxm4.json new file mode 100644 index 00000000000..23191f30bb1 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-62hv-fgc6-fxm4/GHSA-62hv-fgc6-fxm4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62hv-fgc6-fxm4", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-50824" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Batt Insert or Embed Articulate Content into WordPress allows Stored XSS.This issue affects Insert or Embed Articulate Content into WordPress: from n/a through 4.3000000021.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50824" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/insert-or-embed-articulate-content-into-wordpress/wordpress-insert-or-embed-articulate-content-into-wordpress-plugin-4-3000000021-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T15:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-6gj8-gj3v-ccw7/GHSA-6gj8-gj3v-ccw7.json b/advisories/unreviewed/2023/12/GHSA-6gj8-gj3v-ccw7/GHSA-6gj8-gj3v-ccw7.json new file mode 100644 index 00000000000..320c65da26f --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-6gj8-gj3v-ccw7/GHSA-6gj8-gj3v-ccw7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gj8-gj3v-ccw7", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-48116" + ], + "details": "SmarterTools SmarterMail 16.x 8495 through 8664 before 8747 allows stored XSS via a crafted description of a Calendar appointment.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48116" + }, + { + "type": "WEB", + "url": "https://co3us.gitbook.io/write-ups/stored-xss-in-calendar-component-of-smartermail-cve-2023-48116" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-6m9r-7wrx-xmr6/GHSA-6m9r-7wrx-xmr6.json b/advisories/unreviewed/2023/12/GHSA-6m9r-7wrx-xmr6/GHSA-6m9r-7wrx-xmr6.json index 93198a4d420..fe539a35779 100644 --- a/advisories/unreviewed/2023/12/GHSA-6m9r-7wrx-xmr6/GHSA-6m9r-7wrx-xmr6.json +++ b/advisories/unreviewed/2023/12/GHSA-6m9r-7wrx-xmr6/GHSA-6m9r-7wrx-xmr6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6m9r-7wrx-xmr6", - "modified": "2023-12-21T12:30:28Z", + "modified": "2023-12-21T15:30:31Z", "published": "2023-12-21T12:30:28Z", "aliases": [ "CVE-2023-49920" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/mnwd2vcfw3gms6ft6kl951vfbqrxsnjq" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/12/21/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-6ww3-v82p-jv78/GHSA-6ww3-v82p-jv78.json b/advisories/unreviewed/2023/12/GHSA-6ww3-v82p-jv78/GHSA-6ww3-v82p-jv78.json index 5833b70762f..b5610ee990f 100644 --- a/advisories/unreviewed/2023/12/GHSA-6ww3-v82p-jv78/GHSA-6ww3-v82p-jv78.json +++ b/advisories/unreviewed/2023/12/GHSA-6ww3-v82p-jv78/GHSA-6ww3-v82p-jv78.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-401" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/12/GHSA-7j9h-ch38-474r/GHSA-7j9h-ch38-474r.json b/advisories/unreviewed/2023/12/GHSA-7j9h-ch38-474r/GHSA-7j9h-ch38-474r.json new file mode 100644 index 00000000000..24a098d7437 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-7j9h-ch38-474r/GHSA-7j9h-ch38-474r.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7j9h-ch38-474r", + "modified": "2023-12-21T15:30:33Z", + "published": "2023-12-21T15:30:33Z", + "aliases": [ + "CVE-2023-7035" + ], + "details": "A vulnerability was found in automad up to 1.10.9 and classified as problematic. Affected by this issue is some unknown functionality of the file packages\\standard\\templates\\post.php of the component Setting Handler. The manipulation of the argument sitename leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-248684. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7035" + }, + { + "type": "WEB", + "url": "https://github.com/screetsec/VDD/tree/main/Automad%20CMS/Stored%20Cross%20Site%20Scripting%20(XSS)" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.248684" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.248684" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T15:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-7pcg-c7pp-5c42/GHSA-7pcg-c7pp-5c42.json b/advisories/unreviewed/2023/12/GHSA-7pcg-c7pp-5c42/GHSA-7pcg-c7pp-5c42.json new file mode 100644 index 00000000000..17671bf0753 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-7pcg-c7pp-5c42/GHSA-7pcg-c7pp-5c42.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pcg-c7pp-5c42", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2022-45377" + ], + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload for WooCommerce.This issue affects Drag and Drop Multiple File Upload for WooCommerce: from n/a through 1.0.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45377" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/drag-and-drop-multiple-file-upload-for-woocommerce/wordpress-drag-and-drop-multiple-file-upload-for-woocommerce-plugin-1-0-8-multiple-vulnerabilities?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-7xwg-hh9r-4gjx/GHSA-7xwg-hh9r-4gjx.json b/advisories/unreviewed/2023/12/GHSA-7xwg-hh9r-4gjx/GHSA-7xwg-hh9r-4gjx.json new file mode 100644 index 00000000000..b3a9631f868 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-7xwg-hh9r-4gjx/GHSA-7xwg-hh9r-4gjx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xwg-hh9r-4gjx", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-50828" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Vongries Ultimate Dashboard – Custom WordPress Dashboard allows Stored XSS.This issue affects Ultimate Dashboard – Custom WordPress Dashboard: from n/a through 3.7.11.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50828" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/ultimate-dashboard/wordpress-ultimate-dashboard-plugin-3-7-11-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-8f57-wcmg-4jmh/GHSA-8f57-wcmg-4jmh.json b/advisories/unreviewed/2023/12/GHSA-8f57-wcmg-4jmh/GHSA-8f57-wcmg-4jmh.json index 8da03719e73..eec5ca1158c 100644 --- a/advisories/unreviewed/2023/12/GHSA-8f57-wcmg-4jmh/GHSA-8f57-wcmg-4jmh.json +++ b/advisories/unreviewed/2023/12/GHSA-8f57-wcmg-4jmh/GHSA-8f57-wcmg-4jmh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8f57-wcmg-4jmh", - "modified": "2023-12-21T12:30:27Z", + "modified": "2023-12-21T15:30:31Z", "published": "2023-12-21T12:30:27Z", "aliases": [ "CVE-2023-48291" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/3nl0h014274yjlt1hd02z0q78ftyz0z3" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/12/21/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-8qwh-2gcf-fj4g/GHSA-8qwh-2gcf-fj4g.json b/advisories/unreviewed/2023/12/GHSA-8qwh-2gcf-fj4g/GHSA-8qwh-2gcf-fj4g.json new file mode 100644 index 00000000000..e7bfe9e64f4 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-8qwh-2gcf-fj4g/GHSA-8qwh-2gcf-fj4g.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qwh-2gcf-fj4g", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-6145" + ], + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in İstanbul Soft Informatics and Consultancy Limited Company Softomi Advanced C2C Marketplace Software allows SQL Injection.This issue affects Softomi Advanced C2C Marketplace Software: before 12122023.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6145" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-23-0724" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T14:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-8rvj-w5g5-prc2/GHSA-8rvj-w5g5-prc2.json b/advisories/unreviewed/2023/12/GHSA-8rvj-w5g5-prc2/GHSA-8rvj-w5g5-prc2.json new file mode 100644 index 00000000000..73c30445bb8 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-8rvj-w5g5-prc2/GHSA-8rvj-w5g5-prc2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rvj-w5g5-prc2", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-32242" + ], + "details": "Deserialization of Untrusted Data vulnerability in xtemos WoodMart - Multipurpose WooCommerce Theme.This issue affects WoodMart - Multipurpose WooCommerce Theme: from n/a through 1.0.36.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32242" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/woodmart-core/wordpress-woodmart-core-plugin-1-0-36-php-object-injection?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-c82j-mm7v-vfp8/GHSA-c82j-mm7v-vfp8.json b/advisories/unreviewed/2023/12/GHSA-c82j-mm7v-vfp8/GHSA-c82j-mm7v-vfp8.json new file mode 100644 index 00000000000..50a958fffea --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-c82j-mm7v-vfp8/GHSA-c82j-mm7v-vfp8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c82j-mm7v-vfp8", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-49826" + ], + "details": "Deserialization of Untrusted Data vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a through 8.4.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49826" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/soledad/wordpress-soledad-theme-8-4-1-unauthenticated-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-f23h-52hj-99p6/GHSA-f23h-52hj-99p6.json b/advisories/unreviewed/2023/12/GHSA-f23h-52hj-99p6/GHSA-f23h-52hj-99p6.json index 4367e99d003..4b277595952 100644 --- a/advisories/unreviewed/2023/12/GHSA-f23h-52hj-99p6/GHSA-f23h-52hj-99p6.json +++ b/advisories/unreviewed/2023/12/GHSA-f23h-52hj-99p6/GHSA-f23h-52hj-99p6.json @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/zy3klwpv11vl5n65josbfo2fyzxg3dxc" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/12/21/5" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-f7j7-68hw-w26q/GHSA-f7j7-68hw-w26q.json b/advisories/unreviewed/2023/12/GHSA-f7j7-68hw-w26q/GHSA-f7j7-68hw-w26q.json new file mode 100644 index 00000000000..c7db829e409 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-f7j7-68hw-w26q/GHSA-f7j7-68hw-w26q.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7j7-68hw-w26q", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-50822" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Currency.Wiki Currency Converter Widget – Exchange Rates allows Stored XSS.This issue affects Currency Converter Widget – Exchange Rates: from n/a through 3.0.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50822" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/currency-converter-widget/wordpress-currency-converter-widget-plugin-3-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-gxvx-vq8h-p56h/GHSA-gxvx-vq8h-p56h.json b/advisories/unreviewed/2023/12/GHSA-gxvx-vq8h-p56h/GHSA-gxvx-vq8h-p56h.json new file mode 100644 index 00000000000..3ce13d4377c --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-gxvx-vq8h-p56h/GHSA-gxvx-vq8h-p56h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxvx-vq8h-p56h", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-49762" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in AppMySite AppMySite – Create an app with the Best Mobile App Builder.This issue affects AppMySite – Create an app with the Best Mobile App Builder: from n/a through 3.11.0.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49762" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/appmysite/wordpress-appmysite-create-an-app-with-the-best-mobile-app-builder-plugin-3-10-0-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T13:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-hf9h-c8cv-r62j/GHSA-hf9h-c8cv-r62j.json b/advisories/unreviewed/2023/12/GHSA-hf9h-c8cv-r62j/GHSA-hf9h-c8cv-r62j.json new file mode 100644 index 00000000000..1aa624a8f91 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-hf9h-c8cv-r62j/GHSA-hf9h-c8cv-r62j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf9h-c8cv-r62j", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-28421" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Winwar Media WordPress Email Marketing Plugin – WP Email Capture.This issue affects WordPress Email Marketing Plugin – WP Email Capture: from n/a through 3.10.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28421" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-email-capture/wordpress-wp-email-capture-plugin-3-10-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-j28j-v2qr-58x6/GHSA-j28j-v2qr-58x6.json b/advisories/unreviewed/2023/12/GHSA-j28j-v2qr-58x6/GHSA-j28j-v2qr-58x6.json new file mode 100644 index 00000000000..3f8c262c8d5 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-j28j-v2qr-58x6/GHSA-j28j-v2qr-58x6.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j28j-v2qr-58x6", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-50826" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Freshlight Lab Menu Image, Icons made easy allows Stored XSS.This issue affects Menu Image, Icons made easy: from n/a through 3.10.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50826" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/menu-image/wordpress-menu-image-icons-made-easy-plugin-3-10-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-jc8g-9q2p-m8vx/GHSA-jc8g-9q2p-m8vx.json b/advisories/unreviewed/2023/12/GHSA-jc8g-9q2p-m8vx/GHSA-jc8g-9q2p-m8vx.json new file mode 100644 index 00000000000..1b225774933 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-jc8g-9q2p-m8vx/GHSA-jc8g-9q2p-m8vx.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jc8g-9q2p-m8vx", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-48288" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HM Plugin WordPress Job Board and Recruitment Plugin – JobWP.This issue affects WordPress Job Board and Recruitment Plugin – JobWP: from n/a through 2.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48288" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/jobwp/wordpress-jobwp-plugin-2-1-sensitive-data-exposure-on-resume-files-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-jfg8-q228-h5m4/GHSA-jfg8-q228-h5m4.json b/advisories/unreviewed/2023/12/GHSA-jfg8-q228-h5m4/GHSA-jfg8-q228-h5m4.json new file mode 100644 index 00000000000..5f8b402ddef --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-jfg8-q228-h5m4/GHSA-jfg8-q228-h5m4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfg8-q228-h5m4", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-49778" + ], + "details": "Deserialization of Untrusted Data vulnerability in Hakan Demiray Sayfa Sayac.This issue affects Sayfa Sayac: from n/a through 2.6.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49778" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/sayfa-sayac/wordpress-sayfa-sayac-plugin-2-6-unauthenticated-php-object-injection-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T13:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-m4r9-8h98-x643/GHSA-m4r9-8h98-x643.json b/advisories/unreviewed/2023/12/GHSA-m4r9-8h98-x643/GHSA-m4r9-8h98-x643.json new file mode 100644 index 00000000000..afd283bb6d3 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-m4r9-8h98-x643/GHSA-m4r9-8h98-x643.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4r9-8h98-x643", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-47525" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Event Monster – Event Management, Tickets Booking, Upcoming Event allows Stored XSS.This issue affects Event Monster – Event Management, Tickets Booking, Upcoming Event: from n/a through 1.3.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47525" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/event-monster/wordpress-event-monster-plugin-1-3-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-m9vp-5pvm-gxw4/GHSA-m9vp-5pvm-gxw4.json b/advisories/unreviewed/2023/12/GHSA-m9vp-5pvm-gxw4/GHSA-m9vp-5pvm-gxw4.json new file mode 100644 index 00000000000..3f2ce83dbc7 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-m9vp-5pvm-gxw4/GHSA-m9vp-5pvm-gxw4.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9vp-5pvm-gxw4", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-50377" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AB-WP Simple Counter allows Stored XSS.This issue affects Simple Counter: from n/a through 1.0.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50377" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/abwp-simple-counter/wordpress-simple-counter-plugin-1-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-mfr4-4gq8-693m/GHSA-mfr4-4gq8-693m.json b/advisories/unreviewed/2023/12/GHSA-mfr4-4gq8-693m/GHSA-mfr4-4gq8-693m.json new file mode 100644 index 00000000000..235320c0bb3 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-mfr4-4gq8-693m/GHSA-mfr4-4gq8-693m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfr4-4gq8-693m", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-48115" + ], + "details": "SmarterTools SmarterMail 16.x 8495 through 8664 before 8747 allows stored DOM XSS because an XSS protection mechanism is skipped when messageHTML and messagePlainText are set in the same request.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48115" + }, + { + "type": "WEB", + "url": "https://co3us.gitbook.io/write-ups/stored-dom-xss-in-email-body-of-smartermail" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-pxch-wr7m-rwxj/GHSA-pxch-wr7m-rwxj.json b/advisories/unreviewed/2023/12/GHSA-pxch-wr7m-rwxj/GHSA-pxch-wr7m-rwxj.json index 74a2dea6bd4..03dc45f8707 100644 --- a/advisories/unreviewed/2023/12/GHSA-pxch-wr7m-rwxj/GHSA-pxch-wr7m-rwxj.json +++ b/advisories/unreviewed/2023/12/GHSA-pxch-wr7m-rwxj/GHSA-pxch-wr7m-rwxj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pxch-wr7m-rwxj", - "modified": "2023-12-21T12:30:27Z", + "modified": "2023-12-21T15:30:31Z", "published": "2023-12-21T12:30:27Z", "aliases": [ "CVE-2023-47265" @@ -25,6 +25,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/128f3zl375vb1qv93k82zhnwkpl233pr" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/12/21/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/12/GHSA-q6xr-235v-39cm/GHSA-q6xr-235v-39cm.json b/advisories/unreviewed/2023/12/GHSA-q6xr-235v-39cm/GHSA-q6xr-235v-39cm.json new file mode 100644 index 00000000000..8eda39965a3 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-q6xr-235v-39cm/GHSA-q6xr-235v-39cm.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6xr-235v-39cm", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-50119" + ], + "details": "Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-45292. Reason: This record is a reservation duplicate of CVE-2023-45292. Notes: All CVE users should reference CVE-2023-45292 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50119" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-qmhv-fq76-x3j5/GHSA-qmhv-fq76-x3j5.json b/advisories/unreviewed/2023/12/GHSA-qmhv-fq76-x3j5/GHSA-qmhv-fq76-x3j5.json new file mode 100644 index 00000000000..c067fcb3d25 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-qmhv-fq76-x3j5/GHSA-qmhv-fq76-x3j5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmhv-fq76-x3j5", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-48114" + ], + "details": "SmarterTools SmarterMail 16.x 8495 through 8664 before 8747 allows stored XSS by using image/svg+xml and an uploaded SVG document. This occurs because the application tries to allow youtube.com URLs, but actually allows youtube.com followed by an @ character and an attacker-controlled domain name.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48114" + }, + { + "type": "WEB", + "url": "https://co3us.gitbook.io/write-ups/stored-xss-in-email-body-of-smartermail-cve-2023-48114" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-rjjc-gg9m-vhv8/GHSA-rjjc-gg9m-vhv8.json b/advisories/unreviewed/2023/12/GHSA-rjjc-gg9m-vhv8/GHSA-rjjc-gg9m-vhv8.json new file mode 100644 index 00000000000..e10e1f2580b --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-rjjc-gg9m-vhv8/GHSA-rjjc-gg9m-vhv8.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjjc-gg9m-vhv8", + "modified": "2023-12-21T15:30:33Z", + "published": "2023-12-21T15:30:33Z", + "aliases": [ + "CVE-2023-7047" + ], + "details": "\nInadequate validation of permissions when employing remote tools and \nmacros via the context menu within Devolutions Remote Desktop Manager versions 2023.3.31 and \nearlier permits a user to initiate a connection without proper execution\n rights via the remote tools feature. This affects only SQL data sources.\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7047" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2023-0024/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-rw43-gq3v-mchp/GHSA-rw43-gq3v-mchp.json b/advisories/unreviewed/2023/12/GHSA-rw43-gq3v-mchp/GHSA-rw43-gq3v-mchp.json new file mode 100644 index 00000000000..6b3024510a3 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-rw43-gq3v-mchp/GHSA-rw43-gq3v-mchp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rw43-gq3v-mchp", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-47527" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sajjad Hossain Sagor WP Edit Username allows Stored XSS.This issue affects WP Edit Username: from n/a through 1.0.5.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-47527" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-edit-username/wordpress-wp-edit-username-plugin-1-0-5-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T15:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-v968-6pmm-9qc5/GHSA-v968-6pmm-9qc5.json b/advisories/unreviewed/2023/12/GHSA-v968-6pmm-9qc5/GHSA-v968-6pmm-9qc5.json new file mode 100644 index 00000000000..2f5afd12325 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-v968-6pmm-9qc5/GHSA-v968-6pmm-9qc5.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v968-6pmm-9qc5", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-2487" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Smackcoders Export All Posts, Products, Orders, Refunds & Users.This issue affects Export All Posts, Products, Orders, Refunds & Users: from n/a through 2.4.1.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2487" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/wp-ultimate-exporter/wordpress-export-all-posts-products-orders-refunds-users-plugin-2-2-sensitive-data-exposure-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T14:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-wrq3-v46f-59mp/GHSA-wrq3-v46f-59mp.json b/advisories/unreviewed/2023/12/GHSA-wrq3-v46f-59mp/GHSA-wrq3-v46f-59mp.json new file mode 100644 index 00000000000..8649949e811 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-wrq3-v46f-59mp/GHSA-wrq3-v46f-59mp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrq3-v46f-59mp", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-22674" + ], + "details": "Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Hal Gatewood Dashicons + Custom Post Types.This issue affects Dashicons + Custom Post Types: from n/a through 1.0.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22674" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/dashicons-cpt/wordpress-dashicons-custom-post-types-plugin-1-0-2-broken-access-control?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T15:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-x4h7-65jv-x57h/GHSA-x4h7-65jv-x57h.json b/advisories/unreviewed/2023/12/GHSA-x4h7-65jv-x57h/GHSA-x4h7-65jv-x57h.json new file mode 100644 index 00000000000..0a3ab41f5f1 --- /dev/null +++ b/advisories/unreviewed/2023/12/GHSA-x4h7-65jv-x57h/GHSA-x4h7-65jv-x57h.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4h7-65jv-x57h", + "modified": "2023-12-21T15:30:32Z", + "published": "2023-12-21T15:30:32Z", + "aliases": [ + "CVE-2023-50827" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Accredible Accredible Certificates & Open Badges allows Stored XSS.This issue affects Accredible Certificates & Open Badges: from n/a through 1.4.8.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50827" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/accredible-certificates/wordpress-accredible-certificates-open-badges-plugin-1-4-8-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2023-12-21T15:15:12Z" + } +} \ No newline at end of file