From c5dbd853b71d55d537e9e8d00847d21f612a35a5 Mon Sep 17 00:00:00 2001 From: CVE Team Date: Thu, 27 Jul 2023 07:00:33 +0000 Subject: [PATCH] "-Synchronized-Data." --- 2023/39xxx/CVE-2023-39294.json | 18 ++++++++ 2023/39xxx/CVE-2023-39295.json | 18 ++++++++ 2023/39xxx/CVE-2023-39296.json | 18 ++++++++ 2023/39xxx/CVE-2023-39297.json | 18 ++++++++ 2023/39xxx/CVE-2023-39298.json | 18 ++++++++ 2023/39xxx/CVE-2023-39299.json | 18 ++++++++ 2023/39xxx/CVE-2023-39300.json | 18 ++++++++ 2023/39xxx/CVE-2023-39301.json | 18 ++++++++ 2023/39xxx/CVE-2023-39302.json | 18 ++++++++ 2023/39xxx/CVE-2023-39303.json | 18 ++++++++ 2023/3xxx/CVE-2023-3956.json | 80 ++++++++++++++++++++++++++++++++-- 2023/3xxx/CVE-2023-3957.json | 80 ++++++++++++++++++++++++++++++++-- 2023/3xxx/CVE-2023-3969.json | 18 ++++++++ 2023/3xxx/CVE-2023-3970.json | 18 ++++++++ 14 files changed, 368 insertions(+), 8 deletions(-) create mode 100644 2023/39xxx/CVE-2023-39294.json create mode 100644 2023/39xxx/CVE-2023-39295.json create mode 100644 2023/39xxx/CVE-2023-39296.json create mode 100644 2023/39xxx/CVE-2023-39297.json create mode 100644 2023/39xxx/CVE-2023-39298.json create mode 100644 2023/39xxx/CVE-2023-39299.json create mode 100644 2023/39xxx/CVE-2023-39300.json create mode 100644 2023/39xxx/CVE-2023-39301.json create mode 100644 2023/39xxx/CVE-2023-39302.json create mode 100644 2023/39xxx/CVE-2023-39303.json create mode 100644 2023/3xxx/CVE-2023-3969.json create mode 100644 2023/3xxx/CVE-2023-3970.json diff --git a/2023/39xxx/CVE-2023-39294.json b/2023/39xxx/CVE-2023-39294.json new file mode 100644 index 00000000000..ccea32da9a1 --- /dev/null +++ b/2023/39xxx/CVE-2023-39294.json @@ -0,0 +1,18 @@ +{ + "data_type": "CVE", + "data_format": "MITRE", + "data_version": "4.0", + "CVE_data_meta": { + "ID": "CVE-2023-39294", + "ASSIGNER": "cve@mitre.org", + "STATE": "RESERVED" + }, + "description": { + "description_data": [ + { + "lang": "eng", + "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +} \ No newline at end of file diff --git a/2023/39xxx/CVE-2023-39295.json b/2023/39xxx/CVE-2023-39295.json new file mode 100644 index 00000000000..e628713a89b --- /dev/null +++ b/2023/39xxx/CVE-2023-39295.json @@ -0,0 +1,18 @@ +{ + "data_type": "CVE", + "data_format": "MITRE", + "data_version": "4.0", + "CVE_data_meta": { + "ID": "CVE-2023-39295", + "ASSIGNER": "cve@mitre.org", + "STATE": "RESERVED" + }, + "description": { + "description_data": [ + { + "lang": "eng", + "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +} \ No newline at end of file diff --git a/2023/39xxx/CVE-2023-39296.json b/2023/39xxx/CVE-2023-39296.json new file mode 100644 index 00000000000..0b49fe48852 --- /dev/null +++ b/2023/39xxx/CVE-2023-39296.json @@ -0,0 +1,18 @@ +{ + "data_type": "CVE", + "data_format": "MITRE", + "data_version": "4.0", + "CVE_data_meta": { + "ID": "CVE-2023-39296", + "ASSIGNER": "cve@mitre.org", + "STATE": "RESERVED" + }, + "description": { + "description_data": [ + { + "lang": "eng", + "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +} \ No newline at end of file diff --git a/2023/39xxx/CVE-2023-39297.json b/2023/39xxx/CVE-2023-39297.json new file mode 100644 index 00000000000..2bcf9555dad --- /dev/null +++ b/2023/39xxx/CVE-2023-39297.json @@ -0,0 +1,18 @@ +{ + "data_type": "CVE", + "data_format": "MITRE", + "data_version": "4.0", + "CVE_data_meta": { + "ID": "CVE-2023-39297", + "ASSIGNER": "cve@mitre.org", + "STATE": "RESERVED" + }, + "description": { + "description_data": [ + { + "lang": "eng", + "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +} \ No newline at end of file diff --git a/2023/39xxx/CVE-2023-39298.json b/2023/39xxx/CVE-2023-39298.json new file mode 100644 index 00000000000..b055defbf06 --- /dev/null +++ b/2023/39xxx/CVE-2023-39298.json @@ -0,0 +1,18 @@ +{ + "data_type": "CVE", + "data_format": "MITRE", + "data_version": "4.0", + "CVE_data_meta": { + "ID": "CVE-2023-39298", + "ASSIGNER": "cve@mitre.org", + "STATE": "RESERVED" + }, + "description": { + "description_data": [ + { + "lang": "eng", + "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +} \ No newline at end of file diff --git a/2023/39xxx/CVE-2023-39299.json b/2023/39xxx/CVE-2023-39299.json new file mode 100644 index 00000000000..c9b950ccd0c --- /dev/null +++ b/2023/39xxx/CVE-2023-39299.json @@ -0,0 +1,18 @@ +{ + "data_type": "CVE", + "data_format": "MITRE", + "data_version": "4.0", + "CVE_data_meta": { + "ID": "CVE-2023-39299", + "ASSIGNER": "cve@mitre.org", + "STATE": "RESERVED" + }, + "description": { + "description_data": [ + { + "lang": "eng", + "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +} \ No newline at end of file diff --git a/2023/39xxx/CVE-2023-39300.json b/2023/39xxx/CVE-2023-39300.json new file mode 100644 index 00000000000..0348ea59ec8 --- /dev/null +++ b/2023/39xxx/CVE-2023-39300.json @@ -0,0 +1,18 @@ +{ + "data_type": "CVE", + "data_format": "MITRE", + "data_version": "4.0", + "CVE_data_meta": { + "ID": "CVE-2023-39300", + "ASSIGNER": "cve@mitre.org", + "STATE": "RESERVED" + }, + "description": { + "description_data": [ + { + "lang": "eng", + "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +} \ No newline at end of file diff --git a/2023/39xxx/CVE-2023-39301.json b/2023/39xxx/CVE-2023-39301.json new file mode 100644 index 00000000000..e0d6e7972f2 --- /dev/null +++ b/2023/39xxx/CVE-2023-39301.json @@ -0,0 +1,18 @@ +{ + "data_type": "CVE", + "data_format": "MITRE", + "data_version": "4.0", + "CVE_data_meta": { + "ID": "CVE-2023-39301", + "ASSIGNER": "cve@mitre.org", + "STATE": "RESERVED" + }, + "description": { + "description_data": [ + { + "lang": "eng", + "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +} \ No newline at end of file diff --git a/2023/39xxx/CVE-2023-39302.json b/2023/39xxx/CVE-2023-39302.json new file mode 100644 index 00000000000..87309301747 --- /dev/null +++ b/2023/39xxx/CVE-2023-39302.json @@ -0,0 +1,18 @@ +{ + "data_type": "CVE", + "data_format": "MITRE", + "data_version": "4.0", + "CVE_data_meta": { + "ID": "CVE-2023-39302", + "ASSIGNER": "cve@mitre.org", + "STATE": "RESERVED" + }, + "description": { + "description_data": [ + { + "lang": "eng", + "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +} \ No newline at end of file diff --git a/2023/39xxx/CVE-2023-39303.json b/2023/39xxx/CVE-2023-39303.json new file mode 100644 index 00000000000..c41b39c0f06 --- /dev/null +++ b/2023/39xxx/CVE-2023-39303.json @@ -0,0 +1,18 @@ +{ + "data_type": "CVE", + "data_format": "MITRE", + "data_version": "4.0", + "CVE_data_meta": { + "ID": "CVE-2023-39303", + "ASSIGNER": "cve@mitre.org", + "STATE": "RESERVED" + }, + "description": { + "description_data": [ + { + "lang": "eng", + "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +} \ No newline at end of file diff --git a/2023/3xxx/CVE-2023-3956.json b/2023/3xxx/CVE-2023-3956.json index b20b1f5b052..2c69a96e42b 100644 --- a/2023/3xxx/CVE-2023-3956.json +++ b/2023/3xxx/CVE-2023-3956.json @@ -1,17 +1,89 @@ { + "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", - "data_version": "4.0", "CVE_data_meta": { "ID": "CVE-2023-3956", - "ASSIGNER": "cve@mitre.org", - "STATE": "RESERVED" + "ASSIGNER": "security@wordfence.com", + "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of data due to a missing capability check on the 'events_receiver' function in versions up to, and including, 0.0.9.18. This makes it possible for unauthenticated attackers to add, modify or delete post and taxonomy, install, activate or deactivate plugin, change customizer settings, add or modify or delete user including administrator user." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "CWE-862 Missing Authorization" + } + ] + } + ] + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "vendor_name": "instawp", + "product": { + "product_data": [ + { + "product_name": "InstaWP Connect \u2013 1-click WP Staging & Migration (beta)", + "version": { + "version_data": [ + { + "version_affected": "<=", + "version_name": "*", + "version_value": "0.0.9.18" + } + ] + } + } + ] + } + } + ] + } + }, + "references": { + "reference_data": [ + { + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/48e7acf2-61d4-4762-8657-0701910ce69b?source=cve", + "refsource": "MISC", + "name": "https://www.wordfence.com/threat-intel/vulnerabilities/id/48e7acf2-61d4-4762-8657-0701910ce69b?source=cve" + }, + { + "url": "https://plugins.trac.wordpress.org/browser/instawp-connect/tags/0.0.9.18/includes/class-instawp-rest-apis.php#L103", + "refsource": "MISC", + "name": "https://plugins.trac.wordpress.org/browser/instawp-connect/tags/0.0.9.18/includes/class-instawp-rest-apis.php#L103" + }, + { + "url": "https://plugins.trac.wordpress.org/changeset/2942363/instawp-connect#file5", + "refsource": "MISC", + "name": "https://plugins.trac.wordpress.org/changeset/2942363/instawp-connect#file5" + } + ] + }, + "credits": [ + { + "lang": "en", + "value": "Lana Codes" + } + ], + "impact": { + "cvss": [ + { + "version": "3.1", + "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", + "baseScore": 9.8, + "baseSeverity": "CRITICAL" } ] } diff --git a/2023/3xxx/CVE-2023-3957.json b/2023/3xxx/CVE-2023-3957.json index ce3e83d0fbc..4cc0a1cd8e0 100644 --- a/2023/3xxx/CVE-2023-3957.json +++ b/2023/3xxx/CVE-2023-3957.json @@ -1,17 +1,89 @@ { + "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", - "data_version": "4.0", "CVE_data_meta": { "ID": "CVE-2023-3957", - "ASSIGNER": "cve@mitre.org", - "STATE": "RESERVED" + "ASSIGNER": "security@wordfence.com", + "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "The ACF Photo Gallery Field plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient restriction on the 'apg_profile_update' function in versions up to, and including, 1.9. This makes it possible for authenticated attackers, with subscriber-level permissions or above, to update the user metas arbitrarily. The meta value can only be a string." + } + ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "CWE-285 Improper Authorization" + } + ] + } + ] + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "vendor_name": "navzme", + "product": { + "product_data": [ + { + "product_name": "ACF Photo Gallery Field", + "version": { + "version_data": [ + { + "version_affected": "<=", + "version_name": "*", + "version_value": "1.9" + } + ] + } + } + ] + } + } + ] + } + }, + "references": { + "reference_data": [ + { + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/689511e0-1355-4fcb-8a72-d819abc8e9a3?source=cve", + "refsource": "MISC", + "name": "https://www.wordfence.com/threat-intel/vulnerabilities/id/689511e0-1355-4fcb-8a72-d819abc8e9a3?source=cve" + }, + { + "url": "https://plugins.trac.wordpress.org/browser/navz-photo-gallery/tags/1.9/includes/acf_photo_gallery_save.php#L42", + "refsource": "MISC", + "name": "https://plugins.trac.wordpress.org/browser/navz-photo-gallery/tags/1.9/includes/acf_photo_gallery_save.php#L42" + }, + { + "url": "https://plugins.trac.wordpress.org/changeset/2943404/navz-photo-gallery#file0", + "refsource": "MISC", + "name": "https://plugins.trac.wordpress.org/changeset/2943404/navz-photo-gallery#file0" + } + ] + }, + "credits": [ + { + "lang": "en", + "value": "Lana Codes" + } + ], + "impact": { + "cvss": [ + { + "version": "3.1", + "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N", + "baseScore": 4.3, + "baseSeverity": "MEDIUM" } ] } diff --git a/2023/3xxx/CVE-2023-3969.json b/2023/3xxx/CVE-2023-3969.json new file mode 100644 index 00000000000..16c86ae49f4 --- /dev/null +++ b/2023/3xxx/CVE-2023-3969.json @@ -0,0 +1,18 @@ +{ + "data_type": "CVE", + "data_format": "MITRE", + "data_version": "4.0", + "CVE_data_meta": { + "ID": "CVE-2023-3969", + "ASSIGNER": "cve@mitre.org", + "STATE": "RESERVED" + }, + "description": { + "description_data": [ + { + "lang": "eng", + "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +} \ No newline at end of file diff --git a/2023/3xxx/CVE-2023-3970.json b/2023/3xxx/CVE-2023-3970.json new file mode 100644 index 00000000000..9f29808dff6 --- /dev/null +++ b/2023/3xxx/CVE-2023-3970.json @@ -0,0 +1,18 @@ +{ + "data_type": "CVE", + "data_format": "MITRE", + "data_version": "4.0", + "CVE_data_meta": { + "ID": "CVE-2023-3970", + "ASSIGNER": "cve@mitre.org", + "STATE": "RESERVED" + }, + "description": { + "description_data": [ + { + "lang": "eng", + "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +} \ No newline at end of file