diff --git a/CVE-2023/CVE-2023-504xx/CVE-2023-50463.json b/CVE-2023/CVE-2023-504xx/CVE-2023-50463.json new file mode 100644 index 00000000000..e32e726740d --- /dev/null +++ b/CVE-2023/CVE-2023-504xx/CVE-2023-50463.json @@ -0,0 +1,28 @@ +{ + "id": "CVE-2023-50463", + "sourceIdentifier": "cve@mitre.org", + "published": "2023-12-10T23:15:07.247", + "lastModified": "2023-12-10T23:15:07.247", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows attackers to spoof their source IP address via an X-Forwarded-For header, which may bypass a protection mechanism (trusted_proxy directive in reverse_proxy or IP address range restrictions)." + } + ], + "metrics": {}, + "references": [ + { + "url": "https://caddyserver.com/v2", + "source": "cve@mitre.org" + }, + { + "url": "https://github.com/shift72/caddy-geo-ip/issues/4", + "source": "cve@mitre.org" + }, + { + "url": "https://github.com/shift72/caddy-geo-ip/tags", + "source": "cve@mitre.org" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-66xx/CVE-2023-6658.json b/CVE-2023/CVE-2023-66xx/CVE-2023-6658.json new file mode 100644 index 00000000000..276b3bda396 --- /dev/null +++ b/CVE-2023/CVE-2023-66xx/CVE-2023-6658.json @@ -0,0 +1,88 @@ +{ + "id": "CVE-2023-6658", + "sourceIdentifier": "cna@vuldb.com", + "published": "2023-12-10T23:15:07.313", + "lastModified": "2023-12-10T23:15:07.313", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "A vulnerability classified as critical was found in SourceCodester Simple Student Attendance System 1.0. This vulnerability affects unknown code of the file ajax-api.php?action=save_attendance. The manipulation of the argument class_id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-247366 is the identifier assigned to this vulnerability." + } + ], + "metrics": { + "cvssMetricV31": [ + { + "source": "cna@vuldb.com", + "type": "Secondary", + "cvssData": { + "version": "3.1", + "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", + "attackVector": "ADJACENT_NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "LOW", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "LOW", + "integrityImpact": "LOW", + "availabilityImpact": "LOW", + "baseScore": 5.5, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 2.1, + "impactScore": 3.4 + } + ], + "cvssMetricV2": [ + { + "source": "cna@vuldb.com", + "type": "Secondary", + "cvssData": { + "version": "2.0", + "vectorString": "AV:A/AC:L/Au:S/C:P/I:P/A:P", + "accessVector": "ADJACENT_NETWORK", + "accessComplexity": "LOW", + "authentication": "SINGLE", + "confidentialityImpact": "PARTIAL", + "integrityImpact": "PARTIAL", + "availabilityImpact": "PARTIAL", + "baseScore": 5.2 + }, + "baseSeverity": "MEDIUM", + "exploitabilityScore": 5.1, + "impactScore": 6.4, + "acInsufInfo": false, + "obtainAllPrivilege": false, + "obtainUserPrivilege": false, + "obtainOtherPrivilege": false, + "userInteractionRequired": false + } + ] + }, + "weaknesses": [ + { + "source": "cna@vuldb.com", + "type": "Primary", + "description": [ + { + "lang": "en", + "value": "CWE-89" + } + ] + } + ], + "references": [ + { + "url": "https://github.com/daydust/vuln/blob/main/Simple_Student_Attendance_System/ajax-api.php_SQL-injection.md", + "source": "cna@vuldb.com" + }, + { + "url": "https://vuldb.com/?ctiid.247366", + "source": "cna@vuldb.com" + }, + { + "url": "https://vuldb.com/?id.247366", + "source": "cna@vuldb.com" + } + ] +} \ No newline at end of file diff --git a/README.md b/README.md index 18567c3d35a..d4f37d5d51f 100644 --- a/README.md +++ b/README.md @@ -9,13 +9,13 @@ Repository synchronizes with the NVD every 2 hours. ### Last Repository Update ```plain -2023-12-10T23:00:18.100648+00:00 +2023-12-11T00:55:18.290128+00:00 ``` ### Most recent CVE Modification Timestamp synchronized with NVD ```plain -2023-12-10T21:15:07.343000+00:00 +2023-12-10T23:15:07.313000+00:00 ``` ### Last Data Feed Release @@ -29,15 +29,15 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/ ### Total Number of included CVEs ```plain -232693 +232695 ``` ### CVEs added in the last Commit Recently added CVEs: `2` -* [CVE-2023-6656](CVE-2023/CVE-2023-66xx/CVE-2023-6656.json) (`2023-12-10T21:15:07.093`) -* [CVE-2023-6657](CVE-2023/CVE-2023-66xx/CVE-2023-6657.json) (`2023-12-10T21:15:07.343`) +* [CVE-2023-50463](CVE-2023/CVE-2023-504xx/CVE-2023-50463.json) (`2023-12-10T23:15:07.247`) +* [CVE-2023-6658](CVE-2023/CVE-2023-66xx/CVE-2023-6658.json) (`2023-12-10T23:15:07.313`) ### CVEs modified in the last Commit