Auto-Update: 2024-08-25T06:00:17.167317+00:00

This commit is contained in:
cad-safe-bot 2024-08-25 06:03:14 +00:00
parent 20b065f79a
commit 28c01b0b4b
3 changed files with 147 additions and 12 deletions

View File

@ -0,0 +1,137 @@
{
"id": "CVE-2024-8144",
"sourceIdentifier": "cna@vuldb.com",
"published": "2024-08-25T04:15:03.867",
"lastModified": "2024-08-25T04:15:03.867",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component Logo Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used."
}
],
"metrics": {
"cvssMetricV40": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "4.0",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"vulnerableSystemConfidentiality": "NONE",
"vulnerableSystemIntegrity": "LOW",
"vulnerableSystemAvailability": "NONE",
"subsequentSystemConfidentiality": "NONE",
"subsequentSystemIntegrity": "NONE",
"subsequentSystemAvailability": "NONE",
"exploitMaturity": "NOT_DEFINED",
"confidentialityRequirements": "NOT_DEFINED",
"integrityRequirements": "NOT_DEFINED",
"availabilityRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnerableSystemConfidentiality": "NOT_DEFINED",
"modifiedVulnerableSystemIntegrity": "NOT_DEFINED",
"modifiedVulnerableSystemAvailability": "NOT_DEFINED",
"modifiedSubsequentSystemConfidentiality": "NOT_DEFINED",
"modifiedSubsequentSystemIntegrity": "NOT_DEFINED",
"modifiedSubsequentSystemAvailability": "NOT_DEFINED",
"safety": "NOT_DEFINED",
"automatable": "NOT_DEFINED",
"recovery": "NOT_DEFINED",
"valueDensity": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"baseScore": 5.3,
"baseSeverity": "MEDIUM"
}
}
],
"cvssMetricV31": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 3.5,
"baseSeverity": "LOW"
},
"exploitabilityScore": 2.1,
"impactScore": 1.4
}
],
"cvssMetricV2": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "cna@vuldb.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"references": [
{
"url": "https://github.com/acmglz/bug2_report/blob/main/classcms_xss.md",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?ctiid.275725",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?id.275725",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?submit.397217",
"source": "cna@vuldb.com"
}
]
}

View File

@ -13,13 +13,13 @@ Repository synchronizes with the NVD every 2 hours.
### Last Repository Update
```plain
2024-08-25T04:00:17.348010+00:00
2024-08-25T06:00:17.167317+00:00
```
### Most recent CVE Modification Timestamp synchronized with NVD
```plain
2024-08-25T03:15:03.673000+00:00
2024-08-25T04:15:03.867000+00:00
```
### Last Data Feed Release
@ -33,17 +33,14 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/
### Total Number of included CVEs
```plain
261105
261106
```
### CVEs added in the last Commit
Recently added CVEs: `4`
Recently added CVEs: `1`
- [CVE-2024-45244](CVE-2024/CVE-2024-452xx/CVE-2024-45244.json) (`2024-08-25T02:15:03.383`)
- [CVE-2024-8140](CVE-2024/CVE-2024-81xx/CVE-2024-8140.json) (`2024-08-25T02:15:04.163`)
- [CVE-2024-8141](CVE-2024/CVE-2024-81xx/CVE-2024-8141.json) (`2024-08-25T02:15:04.687`)
- [CVE-2024-8142](CVE-2024/CVE-2024-81xx/CVE-2024-8142.json) (`2024-08-25T03:15:03.673`)
- [CVE-2024-8144](CVE-2024/CVE-2024-81xx/CVE-2024-8144.json) (`2024-08-25T04:15:03.867`)
### CVEs modified in the last Commit

View File

@ -258506,7 +258506,7 @@ CVE-2024-45238,0,0,ccc45be69dfe19e1e7a8bdab1dc3635c5b76d3b76fc80d9b03b5db6c4c8e8
CVE-2024-45239,0,0,c2071b3339b557e4b3c067d45324b1f9fd1fd76e10f09111d85f3447f19fffe5,2024-08-24T23:15:04.353000
CVE-2024-4524,0,0,8e732eea1a281702bf1b965cf73e8243f70f2376e5e0521757bce6618382002a,2024-06-04T19:20:41.520000
CVE-2024-45240,0,0,fccbd301154823cd83da805270cd48452cd27b133537c22483ab00d65d1ebe85,2024-08-24T23:15:04.407000
CVE-2024-45244,1,1,6e075e943c98352c2e762d260bf382b0036cbff6ae4e654def3cf374015dfff5,2024-08-25T02:15:03.383000
CVE-2024-45244,0,0,6e075e943c98352c2e762d260bf382b0036cbff6ae4e654def3cf374015dfff5,2024-08-25T02:15:03.383000
CVE-2024-4525,0,0,dfe2a87106534aea559d2a64c000518f6d0b8952ad5d7b752f8fc10ec2414d43,2024-06-04T19:20:41.620000
CVE-2024-4526,0,0,87a45e4eb41404ceb4b9ba3ca9513f18cac2687a381a0d6211a80485bbac625a,2024-06-04T19:20:41.720000
CVE-2024-4527,0,0,c7ad79186f39af6c4287cf90f197f2ec298291b738fc5af7e4ddede8b4e9adfb,2024-06-04T19:20:41.810000
@ -261101,6 +261101,7 @@ CVE-2024-8136,0,0,6ae8a815666d8a02e6809da8fe11df5b3a5993643a37b38c3ca83e4a46c6bb
CVE-2024-8137,0,0,8fb9d58e8a9ec0c32f19e7936e62cda731eeccd1d68d05595a4657e8ebded412,2024-08-24T23:15:04.467000
CVE-2024-8138,0,0,662cfc697aed42ebe5012c339a4ac74f873e6f6212d0f39aaf020aea51d6dc74,2024-08-25T01:15:10.983000
CVE-2024-8139,0,0,5a74fabbf7dcb51ea69cf4a849e9c60a15d389f223354516d8dc1f3e4a5f1496,2024-08-25T01:15:11.300000
CVE-2024-8140,1,1,60bdcb31e72dc8d58ebff5f24a11864be8d911ad4f98a34c83d4ad581bf2f501,2024-08-25T02:15:04.163000
CVE-2024-8141,1,1,5b89c55608dc7c94dcc3a41a381072a0d3a68ce11de5be1e80b6665e2959a8b1,2024-08-25T02:15:04.687000
CVE-2024-8142,1,1,fcb738cd7c7aaf1f9f023d59895853a768ef11a919deeb1ffc545380a5d50560,2024-08-25T03:15:03.673000
CVE-2024-8140,0,0,60bdcb31e72dc8d58ebff5f24a11864be8d911ad4f98a34c83d4ad581bf2f501,2024-08-25T02:15:04.163000
CVE-2024-8141,0,0,5b89c55608dc7c94dcc3a41a381072a0d3a68ce11de5be1e80b6665e2959a8b1,2024-08-25T02:15:04.687000
CVE-2024-8142,0,0,fcb738cd7c7aaf1f9f023d59895853a768ef11a919deeb1ffc545380a5d50560,2024-08-25T03:15:03.673000
CVE-2024-8144,1,1,88fed21edfd93fa7bca725ad2225251a9d109041c2e48809ee1ed796915b95a8,2024-08-25T04:15:03.867000

Can't render this file because it is too large.