"-Synchronized-Data."

This commit is contained in:
CVE Team 2020-05-08 19:01:25 +00:00
parent 364ed80736
commit bc554657fd
No known key found for this signature in database
GPG Key ID: 5708902F06FEF743
3 changed files with 16 additions and 6 deletions

View File

@ -35,7 +35,7 @@
"description_data": [
{
"lang": "eng",
"value": "In Shopizer before version 2.11.0, a script can be injected in various forms and saved in the database, then executed when information is fetched from backend.\n\nThis has been patched in version 2.11.0."
"value": "In Shopizer before version 2.11.0, a script can be injected in various forms and saved in the database, then executed when information is fetched from backend. This has been patched in version 2.11.0."
}
]
},
@ -69,15 +69,15 @@
},
"references": {
"reference_data": [
{
"name": "https://github.com/shopizer-ecommerce/shopizer/security/advisories/GHSA-8pc4-gvfw-634p",
"refsource": "CONFIRM",
"url": "https://github.com/shopizer-ecommerce/shopizer/security/advisories/GHSA-8pc4-gvfw-634p"
},
{
"name": "https://github.com/shopizer-ecommerce/shopizer/commit/929ca0839a80c6f4dad087e0259089908787ad2a",
"refsource": "MISC",
"url": "https://github.com/shopizer-ecommerce/shopizer/commit/929ca0839a80c6f4dad087e0259089908787ad2a"
},
{
"name": "https://github.com/shopizer-ecommerce/shopizer/security/advisories/GHSA-8pc4-gvfw-634p",
"refsource": "CONFIRM",
"url": "https://github.com/shopizer-ecommerce/shopizer/security/advisories/GHSA-8pc4-gvfw-634p"
}
]
},

View File

@ -61,6 +61,11 @@
"refsource": "MISC",
"name": "http://packetstormsecurity.com/files/157591/SolarWinds-MSP-PME-Cache-Service-Insecure-File-Permissions-Code-Execution.html",
"url": "http://packetstormsecurity.com/files/157591/SolarWinds-MSP-PME-Cache-Service-Insecure-File-Permissions-Code-Execution.html"
},
{
"refsource": "FULLDISC",
"name": "20200508 SolarWinds MSP PME Cache Service - Insecure File Permissions / Code Execution",
"url": "http://seclists.org/fulldisclosure/2020/May/23"
}
]
}

View File

@ -56,6 +56,11 @@
"refsource": "CONFIRM",
"name": "https://www.manageengine.com/products/asset-explorer/sp-readme.html",
"url": "https://www.manageengine.com/products/asset-explorer/sp-readme.html"
},
{
"refsource": "FULLDISC",
"name": "20200508 Asset Explorer Windows Agent - Remote Code Execution",
"url": "http://seclists.org/fulldisclosure/2020/May/29"
}
]
}