diff --git a/advisories/unreviewed/2023/07/GHSA-433q-36rv-j5jj/GHSA-433q-36rv-j5jj.json b/advisories/unreviewed/2023/07/GHSA-433q-36rv-j5jj/GHSA-433q-36rv-j5jj.json index ce17d238b90..93a39b142f9 100644 --- a/advisories/unreviewed/2023/07/GHSA-433q-36rv-j5jj/GHSA-433q-36rv-j5jj.json +++ b/advisories/unreviewed/2023/07/GHSA-433q-36rv-j5jj/GHSA-433q-36rv-j5jj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-433q-36rv-j5jj", - "modified": "2023-07-06T19:24:11Z", + "modified": "2023-10-27T00:30:18Z", "published": "2023-07-06T19:24:11Z", "aliases": [ "CVE-2023-0053" ], "details": "SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior have only FTP and Telnet available for device management. Any sensitive information communicated through these protocols, such as credentials, is sent in cleartext. An attacker could obtain sensitive information such as user credentials to gain access to the system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/07/GHSA-fr44-f297-ppg9/GHSA-fr44-f297-ppg9.json b/advisories/unreviewed/2023/07/GHSA-fr44-f297-ppg9/GHSA-fr44-f297-ppg9.json index becc9110a91..50a6983fee9 100644 --- a/advisories/unreviewed/2023/07/GHSA-fr44-f297-ppg9/GHSA-fr44-f297-ppg9.json +++ b/advisories/unreviewed/2023/07/GHSA-fr44-f297-ppg9/GHSA-fr44-f297-ppg9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fr44-f297-ppg9", - "modified": "2023-07-06T19:24:07Z", + "modified": "2023-10-27T00:30:18Z", "published": "2023-07-06T19:24:07Z", "aliases": [ "CVE-2023-0052" ], "details": "SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior allows the execution of commands without credentials. As Telnet and file transfer protocol (FTP) are the only protocols available for device management, an unauthorized user could access the system and modify the device configuration, which could result in the unauthorized user executing unrestricted malicious commands.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/10/GHSA-2228-5m6x-4rqm/GHSA-2228-5m6x-4rqm.json b/advisories/unreviewed/2023/10/GHSA-2228-5m6x-4rqm/GHSA-2228-5m6x-4rqm.json new file mode 100644 index 00000000000..21d4f55430f --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-2228-5m6x-4rqm/GHSA-2228-5m6x-4rqm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2228-5m6x-4rqm", + "modified": "2023-10-27T00:30:18Z", + "published": "2023-10-27T00:30:18Z", + "aliases": [ + "CVE-2018-16739" + ], + "details": "An issue was discovered on certain ABUS TVIP devices. Due to a path traversal in /opt/cgi/admin/filewrite, an attacker can write to files, and thus execute code arbitrarily with root privileges.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-16739" + }, + { + "type": "WEB", + "url": "https://sec.maride.cc/posts/abus/" + }, + { + "type": "WEB", + "url": "https://www.ccc.de/en/updates/2019/update-nicht-verfugbar-hersteller-nicht-zu-erreichen" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-2g3g-vvgw-mw65/GHSA-2g3g-vvgw-mw65.json b/advisories/unreviewed/2023/10/GHSA-2g3g-vvgw-mw65/GHSA-2g3g-vvgw-mw65.json index d8da5771af7..880c38f7c3d 100644 --- a/advisories/unreviewed/2023/10/GHSA-2g3g-vvgw-mw65/GHSA-2g3g-vvgw-mw65.json +++ b/advisories/unreviewed/2023/10/GHSA-2g3g-vvgw-mw65/GHSA-2g3g-vvgw-mw65.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2g3g-vvgw-mw65", - "modified": "2023-10-25T18:32:24Z", + "modified": "2023-10-27T00:30:18Z", "published": "2023-10-25T18:32:24Z", "aliases": [ "CVE-2023-46525" ], "details": "TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function loginRegister.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-3j7c-23m3-57jj/GHSA-3j7c-23m3-57jj.json b/advisories/unreviewed/2023/10/GHSA-3j7c-23m3-57jj/GHSA-3j7c-23m3-57jj.json new file mode 100644 index 00000000000..9f6b66183ff --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-3j7c-23m3-57jj/GHSA-3j7c-23m3-57jj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j7c-23m3-57jj", + "modified": "2023-10-27T00:30:18Z", + "published": "2023-10-27T00:30:18Z", + "aliases": [ + "CVE-2018-17559" + ], + "details": "Due to incorrect access control, unauthenticated remote attackers can view the /video.mjpg video stream of certain ABUS TVIP cameras.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-17559" + }, + { + "type": "WEB", + "url": "https://sec.maride.cc/posts/abus/#cve-2018-17559" + }, + { + "type": "WEB", + "url": "https://www.ccc.de/en/updates/2019/update-nicht-verfugbar-hersteller-nicht-zu-erreichen" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-4mh7-v2h4-6vf9/GHSA-4mh7-v2h4-6vf9.json b/advisories/unreviewed/2023/10/GHSA-4mh7-v2h4-6vf9/GHSA-4mh7-v2h4-6vf9.json new file mode 100644 index 00000000000..86a18bfa7a9 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-4mh7-v2h4-6vf9/GHSA-4mh7-v2h4-6vf9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mh7-v2h4-6vf9", + "modified": "2023-10-27T00:30:18Z", + "published": "2023-10-27T00:30:18Z", + "aliases": [ + "CVE-2023-43352" + ], + "details": "An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager Menu component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43352" + }, + { + "type": "WEB", + "url": "https://github.com/sromanhu/CMSmadesimple-SSTI--Content" + }, + { + "type": "WEB", + "url": "https://github.com/sromanhu/CVE-2023-43352-CMSmadesimple-SSTI--Content" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-5p68-m49r-89rj/GHSA-5p68-m49r-89rj.json b/advisories/unreviewed/2023/10/GHSA-5p68-m49r-89rj/GHSA-5p68-m49r-89rj.json new file mode 100644 index 00000000000..5b1a8460da8 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-5p68-m49r-89rj/GHSA-5p68-m49r-89rj.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5p68-m49r-89rj", + "modified": "2023-10-27T00:30:18Z", + "published": "2023-10-27T00:30:18Z", + "aliases": [ + "CVE-2023-43737" + ], + "details": "Online Art Gallery v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'fnm' parameter of the header.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43737" + }, + { + "type": "WEB", + "url": "https://fluidattacks.com/advisories/ono" + }, + { + "type": "WEB", + "url": "https://https://projectworlds.in/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-5v38-92h7-3886/GHSA-5v38-92h7-3886.json b/advisories/unreviewed/2023/10/GHSA-5v38-92h7-3886/GHSA-5v38-92h7-3886.json index ca401076e29..e7ba9e61b5b 100644 --- a/advisories/unreviewed/2023/10/GHSA-5v38-92h7-3886/GHSA-5v38-92h7-3886.json +++ b/advisories/unreviewed/2023/10/GHSA-5v38-92h7-3886/GHSA-5v38-92h7-3886.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5v38-92h7-3886", - "modified": "2023-10-25T18:32:24Z", + "modified": "2023-10-27T00:30:18Z", "published": "2023-10-25T18:32:24Z", "aliases": [ "CVE-2023-46527" ], "details": "TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function bindRequestHandle.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-76g7-7jq2-pjg7/GHSA-76g7-7jq2-pjg7.json b/advisories/unreviewed/2023/10/GHSA-76g7-7jq2-pjg7/GHSA-76g7-7jq2-pjg7.json index 073bf4c5aea..2bf92f43ca0 100644 --- a/advisories/unreviewed/2023/10/GHSA-76g7-7jq2-pjg7/GHSA-76g7-7jq2-pjg7.json +++ b/advisories/unreviewed/2023/10/GHSA-76g7-7jq2-pjg7/GHSA-76g7-7jq2-pjg7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-76g7-7jq2-pjg7", - "modified": "2023-10-25T18:32:24Z", + "modified": "2023-10-27T00:30:18Z", "published": "2023-10-25T18:32:24Z", "aliases": [ "CVE-2023-46522" ], "details": "TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function deviceInfoRegister.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-7j46-2fmc-fw7w/GHSA-7j46-2fmc-fw7w.json b/advisories/unreviewed/2023/10/GHSA-7j46-2fmc-fw7w/GHSA-7j46-2fmc-fw7w.json new file mode 100644 index 00000000000..417138ae4d5 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-7j46-2fmc-fw7w/GHSA-7j46-2fmc-fw7w.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7j46-2fmc-fw7w", + "modified": "2023-10-27T00:30:18Z", + "published": "2023-10-27T00:30:18Z", + "aliases": [ + "CVE-2023-46374" + ], + "details": "ZenTao Enterprise Edition version 4.1.3 and before is vulnerable to Cross Site Scripting (XSS).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46374" + }, + { + "type": "WEB", + "url": "https://narrow-payment-2cd.notion.site/ZenTao-4-1-3-is-vulnerable-to-Cross-Site-Scripting-xss-CVE-2023-46374-ebdc61e7a88443b481b649764ba66dee" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-7jxg-pm47-89ph/GHSA-7jxg-pm47-89ph.json b/advisories/unreviewed/2023/10/GHSA-7jxg-pm47-89ph/GHSA-7jxg-pm47-89ph.json new file mode 100644 index 00000000000..41f25d01463 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-7jxg-pm47-89ph/GHSA-7jxg-pm47-89ph.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jxg-pm47-89ph", + "modified": "2023-10-27T00:30:18Z", + "published": "2023-10-27T00:30:18Z", + "aliases": [ + "CVE-2018-17878" + ], + "details": "Buffer Overflow vulnerability in certain ABUS TVIP cameras allows attackers to gain control of the program via crafted string sent to sprintf() function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-17878" + }, + { + "type": "WEB", + "url": "https://sec.maride.cc/posts/abus/#cve-2018-17878" + }, + { + "type": "WEB", + "url": "https://www.ccc.de/en/updates/2019/update-nicht-verfugbar-hersteller-nicht-zu-erreichen" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-7qw4-phr3-pm8x/GHSA-7qw4-phr3-pm8x.json b/advisories/unreviewed/2023/10/GHSA-7qw4-phr3-pm8x/GHSA-7qw4-phr3-pm8x.json new file mode 100644 index 00000000000..50443ddc9ea --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-7qw4-phr3-pm8x/GHSA-7qw4-phr3-pm8x.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qw4-phr3-pm8x", + "modified": "2023-10-27T00:30:18Z", + "published": "2023-10-27T00:30:18Z", + "aliases": [ + "CVE-2023-5805" + ], + "details": "A vulnerability was found in SourceCodester Simple Real Estate Portal System 1.0. It has been classified as critical. Affected is an unknown function of the file view_estate.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-243618 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5805" + }, + { + "type": "WEB", + "url": "https://github.com/lxxcute/Bug/blob/main/Real%20Estate%20Portal%20System%20view_estate.php%20has%20Sqlinjection.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.243618" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.243618" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-8992-9q7r-8chp/GHSA-8992-9q7r-8chp.json b/advisories/unreviewed/2023/10/GHSA-8992-9q7r-8chp/GHSA-8992-9q7r-8chp.json index 3905b512f1a..131b786d097 100644 --- a/advisories/unreviewed/2023/10/GHSA-8992-9q7r-8chp/GHSA-8992-9q7r-8chp.json +++ b/advisories/unreviewed/2023/10/GHSA-8992-9q7r-8chp/GHSA-8992-9q7r-8chp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8992-9q7r-8chp", - "modified": "2023-10-25T18:32:24Z", + "modified": "2023-10-27T00:30:18Z", "published": "2023-10-25T18:32:24Z", "aliases": [ "CVE-2023-46521" ], "details": "TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function RegisterRegister.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-92g2-c2g8-rfxp/GHSA-92g2-c2g8-rfxp.json b/advisories/unreviewed/2023/10/GHSA-92g2-c2g8-rfxp/GHSA-92g2-c2g8-rfxp.json index 6c03d907309..b91c7319b52 100644 --- a/advisories/unreviewed/2023/10/GHSA-92g2-c2g8-rfxp/GHSA-92g2-c2g8-rfxp.json +++ b/advisories/unreviewed/2023/10/GHSA-92g2-c2g8-rfxp/GHSA-92g2-c2g8-rfxp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-92g2-c2g8-rfxp", - "modified": "2023-10-25T18:32:24Z", + "modified": "2023-10-27T00:30:18Z", "published": "2023-10-25T18:32:24Z", "aliases": [ "CVE-2023-46526" ], "details": "TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function resetCloudPwdRegister.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-cq8v-q3f4-9cwp/GHSA-cq8v-q3f4-9cwp.json b/advisories/unreviewed/2023/10/GHSA-cq8v-q3f4-9cwp/GHSA-cq8v-q3f4-9cwp.json index 2e16670ad45..ded75314115 100644 --- a/advisories/unreviewed/2023/10/GHSA-cq8v-q3f4-9cwp/GHSA-cq8v-q3f4-9cwp.json +++ b/advisories/unreviewed/2023/10/GHSA-cq8v-q3f4-9cwp/GHSA-cq8v-q3f4-9cwp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cq8v-q3f4-9cwp", - "modified": "2023-10-25T18:32:24Z", + "modified": "2023-10-27T00:30:18Z", "published": "2023-10-25T18:32:24Z", "aliases": [ "CVE-2023-46520" ], "details": "TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function uninstallPluginReqHandle.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-ffqm-rxh4-r75f/GHSA-ffqm-rxh4-r75f.json b/advisories/unreviewed/2023/10/GHSA-ffqm-rxh4-r75f/GHSA-ffqm-rxh4-r75f.json new file mode 100644 index 00000000000..c32d1f70f6d --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-ffqm-rxh4-r75f/GHSA-ffqm-rxh4-r75f.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffqm-rxh4-r75f", + "modified": "2023-10-27T00:30:18Z", + "published": "2023-10-27T00:30:18Z", + "aliases": [ + "CVE-2023-27170" + ], + "details": "Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27170" + }, + { + "type": "WEB", + "url": "https://balwurk.com/cve-2023-27170-improper-limitation-of-a-pathname-to-a-restricted-directory/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-fj49-xvp9-p96q/GHSA-fj49-xvp9-p96q.json b/advisories/unreviewed/2023/10/GHSA-fj49-xvp9-p96q/GHSA-fj49-xvp9-p96q.json new file mode 100644 index 00000000000..65dfe0ff2fa --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-fj49-xvp9-p96q/GHSA-fj49-xvp9-p96q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj49-xvp9-p96q", + "modified": "2023-10-27T00:30:18Z", + "published": "2023-10-27T00:30:18Z", + "aliases": [ + "CVE-2018-17558" + ], + "details": "Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18, TVIP10051 LM.1.6.18, TVIP11050 MG.1.6.03.05, TVIP20550 LM.1.6.18, TVIP10050 LM.1.6.18, TVIP11550 MG.1.6.03, TVIP21050 MG.1.6.03, and TVIP51550 MG.1.6.03 cameras allow remote attackers to execute code as root.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-17558" + }, + { + "type": "WEB", + "url": "https://sec.maride.cc/posts/abus/" + }, + { + "type": "WEB", + "url": "https://www.ccc.de/en/updates/2019/update-nicht-verfugbar-hersteller-nicht-zu-erreichen" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-gh52-2rq4-cqx2/GHSA-gh52-2rq4-cqx2.json b/advisories/unreviewed/2023/10/GHSA-gh52-2rq4-cqx2/GHSA-gh52-2rq4-cqx2.json index 9908e2fa22b..0877d2e8754 100644 --- a/advisories/unreviewed/2023/10/GHSA-gh52-2rq4-cqx2/GHSA-gh52-2rq4-cqx2.json +++ b/advisories/unreviewed/2023/10/GHSA-gh52-2rq4-cqx2/GHSA-gh52-2rq4-cqx2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gh52-2rq4-cqx2", - "modified": "2023-10-25T18:32:25Z", + "modified": "2023-10-27T00:30:18Z", "published": "2023-10-25T18:32:25Z", "aliases": [ "CVE-2023-46535" ], "details": "TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function getResetVeriRegister.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-hxv9-4gxx-v284/GHSA-hxv9-4gxx-v284.json b/advisories/unreviewed/2023/10/GHSA-hxv9-4gxx-v284/GHSA-hxv9-4gxx-v284.json new file mode 100644 index 00000000000..5fd751e8824 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-hxv9-4gxx-v284/GHSA-hxv9-4gxx-v284.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxv9-4gxx-v284", + "modified": "2023-10-27T00:30:18Z", + "published": "2023-10-27T00:30:18Z", + "aliases": [ + "CVE-2023-42406" + ], + "details": "SQL injection vulnerability in D-Link Online behavior audit gateway DAR-7000 V31R02B1413C allows a remote attacker to obtain sensitive information and execute arbitrary code via the editrole.php component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42406" + }, + { + "type": "WEB", + "url": "https://github.com/flyyue2001/cve/blob/main/D-LINK%20-DAR-7000_sql_:sysmanage:editrole.php.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-jfmm-v8pp-89h8/GHSA-jfmm-v8pp-89h8.json b/advisories/unreviewed/2023/10/GHSA-jfmm-v8pp-89h8/GHSA-jfmm-v8pp-89h8.json index e04552f07ae..fcf6baea884 100644 --- a/advisories/unreviewed/2023/10/GHSA-jfmm-v8pp-89h8/GHSA-jfmm-v8pp-89h8.json +++ b/advisories/unreviewed/2023/10/GHSA-jfmm-v8pp-89h8/GHSA-jfmm-v8pp-89h8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jfmm-v8pp-89h8", - "modified": "2023-10-25T18:32:25Z", + "modified": "2023-10-27T00:30:18Z", "published": "2023-10-25T18:32:25Z", "aliases": [ "CVE-2023-46539" ], "details": "TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function registerRequestHandle.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-jpq4-mchv-jv8r/GHSA-jpq4-mchv-jv8r.json b/advisories/unreviewed/2023/10/GHSA-jpq4-mchv-jv8r/GHSA-jpq4-mchv-jv8r.json new file mode 100644 index 00000000000..019bd419a9e --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-jpq4-mchv-jv8r/GHSA-jpq4-mchv-jv8r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpq4-mchv-jv8r", + "modified": "2023-10-27T00:30:18Z", + "published": "2023-10-27T00:30:18Z", + "aliases": [ + "CVE-2023-38328" + ], + "details": "An issue was discovered in eGroupWare 17.1.20190111. An Improper Password Storage vulnerability affects the setup panel of under setup/manageheader.php, which allows authenticated remote attackers with administrator credentials to read a cleartext database password.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38328" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-jr68-phq8-rwh5/GHSA-jr68-phq8-rwh5.json b/advisories/unreviewed/2023/10/GHSA-jr68-phq8-rwh5/GHSA-jr68-phq8-rwh5.json new file mode 100644 index 00000000000..ee45900c139 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-jr68-phq8-rwh5/GHSA-jr68-phq8-rwh5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr68-phq8-rwh5", + "modified": "2023-10-27T00:30:18Z", + "published": "2023-10-27T00:30:18Z", + "aliases": [ + "CVE-2023-44268" + ], + "details": "Online Art Gallery v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'gender' parameter of the header.php resource does not validate the characters received and they are sent unfiltered to the database.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-44268" + }, + { + "type": "WEB", + "url": "https://fluidattacks.com/advisories/ono" + }, + { + "type": "WEB", + "url": "https://https://projectworlds.in/" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-m98r-vcx2-w27j/GHSA-m98r-vcx2-w27j.json b/advisories/unreviewed/2023/10/GHSA-m98r-vcx2-w27j/GHSA-m98r-vcx2-w27j.json index b2d070bd7d9..2c88fe6eec3 100644 --- a/advisories/unreviewed/2023/10/GHSA-m98r-vcx2-w27j/GHSA-m98r-vcx2-w27j.json +++ b/advisories/unreviewed/2023/10/GHSA-m98r-vcx2-w27j/GHSA-m98r-vcx2-w27j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m98r-vcx2-w27j", - "modified": "2023-10-25T18:32:25Z", + "modified": "2023-10-27T00:30:18Z", "published": "2023-10-25T18:32:25Z", "aliases": [ "CVE-2023-46537" ], "details": "TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function getRegVeriRegister.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-pqpq-95jv-jqmc/GHSA-pqpq-95jv-jqmc.json b/advisories/unreviewed/2023/10/GHSA-pqpq-95jv-jqmc/GHSA-pqpq-95jv-jqmc.json index 1f9c15f02ed..57c17c1f891 100644 --- a/advisories/unreviewed/2023/10/GHSA-pqpq-95jv-jqmc/GHSA-pqpq-95jv-jqmc.json +++ b/advisories/unreviewed/2023/10/GHSA-pqpq-95jv-jqmc/GHSA-pqpq-95jv-jqmc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pqpq-95jv-jqmc", - "modified": "2023-10-26T21:30:21Z", + "modified": "2023-10-27T00:30:18Z", "published": "2023-10-26T21:30:21Z", "aliases": [ "CVE-2023-44267" diff --git a/advisories/unreviewed/2023/10/GHSA-q7mm-qvfp-88hm/GHSA-q7mm-qvfp-88hm.json b/advisories/unreviewed/2023/10/GHSA-q7mm-qvfp-88hm/GHSA-q7mm-qvfp-88hm.json new file mode 100644 index 00000000000..7c7833cad0e --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-q7mm-qvfp-88hm/GHSA-q7mm-qvfp-88hm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7mm-qvfp-88hm", + "modified": "2023-10-27T00:30:18Z", + "published": "2023-10-27T00:30:18Z", + "aliases": [ + "CVE-2023-42188" + ], + "details": "IceCMS v2.0.1 is vulnerable to Cross Site Request Forgery (CSRF).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42188" + }, + { + "type": "WEB", + "url": "https://github.com/Thecosy/IceCMS/issues/17" + }, + { + "type": "WEB", + "url": "https://topdayplus.github.io/2023/10/27/CVE-deatail/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-rfrw-m2jx-m42j/GHSA-rfrw-m2jx-m42j.json b/advisories/unreviewed/2023/10/GHSA-rfrw-m2jx-m42j/GHSA-rfrw-m2jx-m42j.json index 06ff5027328..d5851dfad6a 100644 --- a/advisories/unreviewed/2023/10/GHSA-rfrw-m2jx-m42j/GHSA-rfrw-m2jx-m42j.json +++ b/advisories/unreviewed/2023/10/GHSA-rfrw-m2jx-m42j/GHSA-rfrw-m2jx-m42j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rfrw-m2jx-m42j", - "modified": "2023-10-25T18:32:25Z", + "modified": "2023-10-27T00:30:18Z", "published": "2023-10-25T18:32:25Z", "aliases": [ "CVE-2023-46536" ], "details": "TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function chkRegVeriRegister.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-rgg4-rgq7-84pp/GHSA-rgg4-rgq7-84pp.json b/advisories/unreviewed/2023/10/GHSA-rgg4-rgq7-84pp/GHSA-rgg4-rgq7-84pp.json new file mode 100644 index 00000000000..dad6294896f --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-rgg4-rgq7-84pp/GHSA-rgg4-rgq7-84pp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgg4-rgq7-84pp", + "modified": "2023-10-27T00:30:18Z", + "published": "2023-10-27T00:30:18Z", + "aliases": [ + "CVE-2018-17879" + ], + "details": "An issue was discovered on certain ABUS TVIP cameras. The CGI scripts allow remote attackers to execute code via system() as root. There are several injection points in various scripts.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-17879" + }, + { + "type": "WEB", + "url": "https://sec.maride.cc/posts/abus/#cve-2018-17879" + }, + { + "type": "WEB", + "url": "https://www.ccc.de/en/updates/2019/update-nicht-verfugbar-hersteller-nicht-zu-erreichen" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-rgx4-jh4p-m887/GHSA-rgx4-jh4p-m887.json b/advisories/unreviewed/2023/10/GHSA-rgx4-jh4p-m887/GHSA-rgx4-jh4p-m887.json index 18f19488adf..83ed7dd495a 100644 --- a/advisories/unreviewed/2023/10/GHSA-rgx4-jh4p-m887/GHSA-rgx4-jh4p-m887.json +++ b/advisories/unreviewed/2023/10/GHSA-rgx4-jh4p-m887/GHSA-rgx4-jh4p-m887.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rgx4-jh4p-m887", - "modified": "2023-10-25T18:32:25Z", + "modified": "2023-10-27T00:30:18Z", "published": "2023-10-25T18:32:25Z", "aliases": [ "CVE-2023-46534" ], "details": "TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function modifyAccPwdRegister.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-vj2w-frgg-mff6/GHSA-vj2w-frgg-mff6.json b/advisories/unreviewed/2023/10/GHSA-vj2w-frgg-mff6/GHSA-vj2w-frgg-mff6.json index 739e9269873..247628c5264 100644 --- a/advisories/unreviewed/2023/10/GHSA-vj2w-frgg-mff6/GHSA-vj2w-frgg-mff6.json +++ b/advisories/unreviewed/2023/10/GHSA-vj2w-frgg-mff6/GHSA-vj2w-frgg-mff6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vj2w-frgg-mff6", - "modified": "2023-10-25T18:32:25Z", + "modified": "2023-10-27T00:30:18Z", "published": "2023-10-25T18:32:25Z", "aliases": [ "CVE-2023-46538" ], "details": "TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function chkResetVeriRegister.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false, diff --git a/advisories/unreviewed/2023/10/GHSA-xpmf-rjrc-7rc4/GHSA-xpmf-rjrc-7rc4.json b/advisories/unreviewed/2023/10/GHSA-xpmf-rjrc-7rc4/GHSA-xpmf-rjrc-7rc4.json new file mode 100644 index 00000000000..9eeaa220289 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-xpmf-rjrc-7rc4/GHSA-xpmf-rjrc-7rc4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpmf-rjrc-7rc4", + "modified": "2023-10-27T00:30:18Z", + "published": "2023-10-27T00:30:18Z", + "aliases": [ + "CVE-2023-46491" + ], + "details": "ZenTao Biz version 4.1.3 and before has a Cross Site Scripting (XSS) vulnerability in the Version Library.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46491" + }, + { + "type": "WEB", + "url": "https://foremost-smash-52a.notion.site/Zentao-Authorized-XSS-Vulnerability-CVE-2023-46491-eea8cbfe2fab4ea78a174e5275309759" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-xx33-j3mf-gffc/GHSA-xx33-j3mf-gffc.json b/advisories/unreviewed/2023/10/GHSA-xx33-j3mf-gffc/GHSA-xx33-j3mf-gffc.json index 3152068a0de..ac53c58ff51 100644 --- a/advisories/unreviewed/2023/10/GHSA-xx33-j3mf-gffc/GHSA-xx33-j3mf-gffc.json +++ b/advisories/unreviewed/2023/10/GHSA-xx33-j3mf-gffc/GHSA-xx33-j3mf-gffc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xx33-j3mf-gffc", - "modified": "2023-10-25T18:32:24Z", + "modified": "2023-10-27T00:30:18Z", "published": "2023-10-25T18:32:24Z", "aliases": [ "CVE-2023-46523" ], "details": "TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function upgradeInfoRegister.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": null, "github_reviewed": false,