From a0d0f75a02523cf9ccccc55c2541c532d244cbd9 Mon Sep 17 00:00:00 2001 From: CVE Team Date: Fri, 8 Mar 2024 13:00:33 +0000 Subject: [PATCH] "-Synchronized-Data." --- 2023/40xxx/CVE-2023-40834.json | 2 +- 2023/40xxx/CVE-2023-40930.json | 2 +- 2024/28xxx/CVE-2024-28752.json | 18 +++++++ 2024/2xxx/CVE-2024-2317.json | 95 ++++++++++++++++++++++++++++++++-- 4 files changed, 111 insertions(+), 6 deletions(-) create mode 100644 2024/28xxx/CVE-2024-28752.json diff --git a/2023/40xxx/CVE-2023-40834.json b/2023/40xxx/CVE-2023-40834.json index 4b7cf084306..2ca03cd9661 100644 --- a/2023/40xxx/CVE-2023-40834.json +++ b/2023/40xxx/CVE-2023-40834.json @@ -34,7 +34,7 @@ "description_data": [ { "lang": "eng", - "value": "OpenCart v4.0.2.2 is vulnerable to Brute Force Attack." + "value": "OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated attackers to gain access to the application via a brute force attack." } ] }, diff --git a/2023/40xxx/CVE-2023-40930.json b/2023/40xxx/CVE-2023-40930.json index c209a4300ac..e4421fb79db 100644 --- a/2023/40xxx/CVE-2023-40930.json +++ b/2023/40xxx/CVE-2023-40930.json @@ -34,7 +34,7 @@ "description_data": [ { "lang": "eng", - "value": "Skyworth 3.0 OS is vulnerable to Directory Traversal." + "value": "An issue in the directory /system/bin/blkid of Skyworth v3.0 allows attackers to perform a directory traversal via mounting the Udisk to /mnt/." } ] }, diff --git a/2024/28xxx/CVE-2024-28752.json b/2024/28xxx/CVE-2024-28752.json new file mode 100644 index 00000000000..69df35d91ef --- /dev/null +++ b/2024/28xxx/CVE-2024-28752.json @@ -0,0 +1,18 @@ +{ + "data_type": "CVE", + "data_format": "MITRE", + "data_version": "4.0", + "CVE_data_meta": { + "ID": "CVE-2024-28752", + "ASSIGNER": "cve@mitre.org", + "STATE": "RESERVED" + }, + "description": { + "description_data": [ + { + "lang": "eng", + "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +} \ No newline at end of file diff --git a/2024/2xxx/CVE-2024-2317.json b/2024/2xxx/CVE-2024-2317.json index 350d74bbf2b..e65d6cc430d 100644 --- a/2024/2xxx/CVE-2024-2317.json +++ b/2024/2xxx/CVE-2024-2317.json @@ -1,17 +1,104 @@ { + "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", - "data_version": "4.0", "CVE_data_meta": { "ID": "CVE-2024-2317", - "ASSIGNER": "cve@mitre.org", - "STATE": "RESERVED" + "ASSIGNER": "cna@vuldb.com", + "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "A vulnerability was found in Bdtask Hospital AutoManager up to 20240227 and classified as problematic. This issue affects some unknown processing of the file /prescription/prescription/delete/ of the component Prescription Page. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-256271. NOTE: The vendor was contacted early about this disclosure but did not respond in any way." + }, + { + "lang": "deu", + "value": "Eine problematische Schwachstelle wurde in Bdtask Hospital AutoManager bis 20240227 gefunden. Es geht hierbei um eine nicht n\u00e4her spezifizierte Funktion der Datei /prescription/prescription/delete/ der Komponente Prescription Page. Durch Manipulation mit unbekannten Daten kann eine improper authorization-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk angegangen werden. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "CWE-285 Improper Authorization", + "cweId": "CWE-285" + } + ] + } + ] + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "vendor_name": "Bdtask", + "product": { + "product_data": [ + { + "product_name": "Hospital AutoManager", + "version": { + "version_data": [ + { + "version_affected": "=", + "version_value": "20240227" + } + ] + } + } + ] + } + } + ] + } + }, + "references": { + "reference_data": [ + { + "url": "https://vuldb.com/?id.256271", + "refsource": "MISC", + "name": "https://vuldb.com/?id.256271" + }, + { + "url": "https://vuldb.com/?ctiid.256271", + "refsource": "MISC", + "name": "https://vuldb.com/?ctiid.256271" + }, + { + "url": "https://drive.google.com/file/d/13-Fxw8fw3VP1PvL0fYvDBVlpTDQHyCkc/view?usp=sharing", + "refsource": "MISC", + "name": "https://drive.google.com/file/d/13-Fxw8fw3VP1PvL0fYvDBVlpTDQHyCkc/view?usp=sharing" + } + ] + }, + "credits": [ + { + "lang": "en", + "value": "srivishnu (VulDB User)" + } + ], + "impact": { + "cvss": [ + { + "version": "3.1", + "baseScore": 3.8, + "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L", + "baseSeverity": "LOW" + }, + { + "version": "3.0", + "baseScore": 3.8, + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L", + "baseSeverity": "LOW" + }, + { + "version": "2.0", + "baseScore": 4.7, + "vectorString": "AV:N/AC:L/Au:M/C:N/I:P/A:P" } ] }