diff --git a/advisories/unreviewed/2023/10/GHSA-2pfv-q6j2-pcrf/GHSA-2pfv-q6j2-pcrf.json b/advisories/unreviewed/2023/10/GHSA-2pfv-q6j2-pcrf/GHSA-2pfv-q6j2-pcrf.json index 8437f6d6aea..20a396b6941 100644 --- a/advisories/unreviewed/2023/10/GHSA-2pfv-q6j2-pcrf/GHSA-2pfv-q6j2-pcrf.json +++ b/advisories/unreviewed/2023/10/GHSA-2pfv-q6j2-pcrf/GHSA-2pfv-q6j2-pcrf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2pfv-q6j2-pcrf", - "modified": "2023-10-04T15:30:35Z", + "modified": "2024-01-02T00:30:21Z", "published": "2023-10-04T15:30:35Z", "aliases": [ "CVE-2023-4380" @@ -38,7 +38,7 @@ "cwe_ids": [ "CWE-532" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-04T15:15:12Z" diff --git a/advisories/unreviewed/2024/01/GHSA-8qwg-h3wf-mwx5/GHSA-8qwg-h3wf-mwx5.json b/advisories/unreviewed/2024/01/GHSA-8qwg-h3wf-mwx5/GHSA-8qwg-h3wf-mwx5.json new file mode 100644 index 00000000000..87c949ffee1 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-8qwg-h3wf-mwx5/GHSA-8qwg-h3wf-mwx5.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qwg-h3wf-mwx5", + "modified": "2024-01-02T00:30:21Z", + "published": "2024-01-02T00:30:21Z", + "aliases": [ + "CVE-2024-0183" + ], + "details": "A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/students.php of the component NIA Office. The manipulation leads to basic cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249441 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0183" + }, + { + "type": "WEB", + "url": "https://mega.nz/file/SB8ylCxQ#vSaXJwbNjeG-KXatgkxE8XI6Cmnv-A_Sg2IjvoJZs0E" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249441" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249441" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-01T23:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-x5vr-jp46-rrhq/GHSA-x5vr-jp46-rrhq.json b/advisories/unreviewed/2024/01/GHSA-x5vr-jp46-rrhq/GHSA-x5vr-jp46-rrhq.json new file mode 100644 index 00000000000..4d0dbbea680 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-x5vr-jp46-rrhq/GHSA-x5vr-jp46-rrhq.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5vr-jp46-rrhq", + "modified": "2024-01-02T00:30:21Z", + "published": "2024-01-02T00:30:21Z", + "aliases": [ + "CVE-2024-0184" + ], + "details": "A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/edit_teacher.php of the component Add Enginer. The manipulation of the argument Firstname/Lastname leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-249442 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0184" + }, + { + "type": "WEB", + "url": "https://mega.nz/file/eN8yEKSA#YCJNH1v4BKOG2xyxOZYPIuO3Oz7biv2ugfarAI5n_3k" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249442" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249442" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-02T00:15:08Z" + } +} \ No newline at end of file