From 3985b4ea5db2d989359e17c3b128e6706d455ea7 Mon Sep 17 00:00:00 2001 From: cad-safe-bot Date: Tue, 4 Jun 2024 06:03:33 +0000 Subject: [PATCH] Auto-Update: 2024-06-04T06:00:38.010804+00:00 --- CVE-2024/CVE-2024-38xx/CVE-2024-3888.json | 47 +++++++++++++++++++++++ README.md | 19 +++------ _state.csv | 17 ++++---- 3 files changed, 62 insertions(+), 21 deletions(-) create mode 100644 CVE-2024/CVE-2024-38xx/CVE-2024-3888.json diff --git a/CVE-2024/CVE-2024-38xx/CVE-2024-3888.json b/CVE-2024/CVE-2024-38xx/CVE-2024-3888.json new file mode 100644 index 00000000000..29e30b4b139 --- /dev/null +++ b/CVE-2024/CVE-2024-38xx/CVE-2024-3888.json @@ -0,0 +1,47 @@ +{ + "id": "CVE-2024-3888", + "sourceIdentifier": "security@wordfence.com", + "published": "2024-06-04T05:15:49.330", + "lastModified": "2024-06-04T05:15:49.330", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button shortcode in all versions up to, and including, 4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: The vulnerable code in this plugin is specifically tied to the tagDiv Newspaper theme. If another theme is installed (e.g., NewsMag), this code may not be present." + } + ], + "metrics": { + "cvssMetricV31": [ + { + "source": "security@wordfence.com", + "type": "Primary", + "cvssData": { + "version": "3.1", + "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "LOW", + "userInteraction": "NONE", + "scope": "CHANGED", + "confidentialityImpact": "LOW", + "integrityImpact": "LOW", + "availabilityImpact": "NONE", + "baseScore": 6.4, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 3.1, + "impactScore": 2.7 + } + ] + }, + "references": [ + { + "url": "https://tagdiv.com/newspaper/", + "source": "security@wordfence.com" + }, + { + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/466fc6f3-7b2d-4975-a838-16e27bc9f9b5?source=cve", + "source": "security@wordfence.com" + } + ] +} \ No newline at end of file diff --git a/README.md b/README.md index 95b4dc12ce9..7732fb19b99 100644 --- a/README.md +++ b/README.md @@ -13,13 +13,13 @@ Repository synchronizes with the NVD every 2 hours. ### Last Repository Update ```plain -2024-06-04T04:00:37.948068+00:00 +2024-06-04T06:00:38.010804+00:00 ``` ### Most recent CVE Modification Timestamp synchronized with NVD ```plain -2024-06-04T02:15:49.620000+00:00 +2024-06-04T05:15:49.330000+00:00 ``` ### Last Data Feed Release @@ -33,27 +33,20 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/ ### Total Number of included CVEs ```plain -252495 +252496 ``` ### CVEs added in the last Commit -Recently added CVEs: `7` +Recently added CVEs: `1` -- [CVE-2024-29972](CVE-2024/CVE-2024-299xx/CVE-2024-29972.json) (`2024-06-04T02:15:47.960`) -- [CVE-2024-29973](CVE-2024/CVE-2024-299xx/CVE-2024-29973.json) (`2024-06-04T02:15:48.290`) -- [CVE-2024-29974](CVE-2024/CVE-2024-299xx/CVE-2024-29974.json) (`2024-06-04T02:15:48.517`) -- [CVE-2024-29975](CVE-2024/CVE-2024-299xx/CVE-2024-29975.json) (`2024-06-04T02:15:48.760`) -- [CVE-2024-29976](CVE-2024/CVE-2024-299xx/CVE-2024-29976.json) (`2024-06-04T02:15:49.050`) -- [CVE-2024-4552](CVE-2024/CVE-2024-45xx/CVE-2024-4552.json) (`2024-06-04T02:15:49.417`) -- [CVE-2024-4870](CVE-2024/CVE-2024-48xx/CVE-2024-4870.json) (`2024-06-04T02:15:49.620`) +- [CVE-2024-3888](CVE-2024/CVE-2024-38xx/CVE-2024-3888.json) (`2024-06-04T05:15:49.330`) ### CVEs modified in the last Commit -Recently modified CVEs: `1` +Recently modified CVEs: `0` -- [CVE-2024-3802](CVE-2024/CVE-2024-38xx/CVE-2024-3802.json) (`2024-06-04T02:15:49.290`) ## Download and Usage diff --git a/_state.csv b/_state.csv index 07ab3cc7dd0..3c05be06bdf 100644 --- a/_state.csv +++ b/_state.csv @@ -247868,11 +247868,11 @@ CVE-2024-29967,0,0,3697c6ed64dbd076ce60ecfa47f5b907fa72bc99eadb005dc57c9cc60eb5d CVE-2024-29968,0,0,76c6a6d6e702eab18ed6ce28244f46395278fc23ed27747337db2cb902c35659,2024-04-19T13:10:25.637000 CVE-2024-29969,0,0,f16f6487ea10360dec838824d2148298e2039f6602688dd9caf524b4969c6186,2024-04-19T13:10:25.637000 CVE-2024-2997,0,0,3a578291c3b241bab600655a4ba011b593bae43f4bacaa35e28ecb654fca1f55,2024-05-17T02:38:41.790000 -CVE-2024-29972,1,1,bbdf215dbb4ef695f3d59464f2484bc6cbd8646a26b1277c868be99b91981545,2024-06-04T02:15:47.960000 -CVE-2024-29973,1,1,4a1a9a073635df852cb094c56afb1c721f34a3bf203ee7f60dfbf9309c8c6060,2024-06-04T02:15:48.290000 -CVE-2024-29974,1,1,adab74f4b1aa0d1b33cfaa7dd0b9c9a682b143c9f06c8d84f22c9e59890d7778,2024-06-04T02:15:48.517000 -CVE-2024-29975,1,1,f371c119f1b7eedb86c253bd9c3e0778ac5d957b1d91d2c17f509e443809c79f,2024-06-04T02:15:48.760000 -CVE-2024-29976,1,1,89a1b759948e1a9232fd6bdb055b512851fa19acf02a05236818d0be59c74c41,2024-06-04T02:15:49.050000 +CVE-2024-29972,0,0,bbdf215dbb4ef695f3d59464f2484bc6cbd8646a26b1277c868be99b91981545,2024-06-04T02:15:47.960000 +CVE-2024-29973,0,0,4a1a9a073635df852cb094c56afb1c721f34a3bf203ee7f60dfbf9309c8c6060,2024-06-04T02:15:48.290000 +CVE-2024-29974,0,0,adab74f4b1aa0d1b33cfaa7dd0b9c9a682b143c9f06c8d84f22c9e59890d7778,2024-06-04T02:15:48.517000 +CVE-2024-29975,0,0,f371c119f1b7eedb86c253bd9c3e0778ac5d957b1d91d2c17f509e443809c79f,2024-06-04T02:15:48.760000 +CVE-2024-29976,0,0,89a1b759948e1a9232fd6bdb055b512851fa19acf02a05236818d0be59c74c41,2024-06-04T02:15:49.050000 CVE-2024-2998,0,0,eefb5ffb4f4c69125c8918f19ada8e94baebaa500baf95dbd5f811afe3390da3,2024-05-17T02:38:41.883000 CVE-2024-29981,0,0,b762af1b8e0b46a6fed26152fe7346562730b9b9166ba9906ede0af07fe94bd1,2024-05-28T23:15:17.270000 CVE-2024-29982,0,0,64f04207a570cedc766e0c25e46008bcac3eae2a59a1b82cc7357dd602bc9510,2024-04-10T13:24:00.070000 @@ -251476,7 +251476,7 @@ CVE-2024-3794,0,0,153385e096cd7f2ece15b2458b2e9fc3a616d4e8c794288f506409f055c027 CVE-2024-3795,0,0,394c789f966243db6d7a4bfee356db0989703de57fa4252b7833b38d6036f026,2024-05-14T16:11:39.510000 CVE-2024-3796,0,0,8b56f1ae3498f70c780deb392dd70e4b0e2eb55d8dc491cebdead02f06bb596a,2024-05-14T16:11:39.510000 CVE-2024-3797,0,0,ee6a5db4c86b7a1cb7dddd0f923d514d4da716af84fa2cbea88db014d700ce37,2024-05-17T02:40:08.123000 -CVE-2024-3802,0,1,aaa997a68afe711762ac8536c5d0fad15740edaa6785e851a1495f0cf1f43e75,2024-06-04T02:15:49.290000 +CVE-2024-3802,0,0,aaa997a68afe711762ac8536c5d0fad15740edaa6785e851a1495f0cf1f43e75,2024-06-04T02:15:49.290000 CVE-2024-3803,0,0,cefb64222fdf80706b1a9eb17e095bbe2f795f698686df2fa7fab7399b51955d,2024-05-17T02:40:08.240000 CVE-2024-3804,0,0,b7a9587e28845ae1f668a1a806513f45c5c76ad839ab74db40f9b52358b0e2eb,2024-05-17T02:40:08.330000 CVE-2024-3806,0,0,de873f8585a077f47d9a3aa2ddc3d8a1a22e9124cbb6f60c98787e1f14a35570,2024-05-14T16:11:39.510000 @@ -251547,6 +251547,7 @@ CVE-2024-3882,0,0,43bad73eafa6ac43c909cb529fe3ba674146baf41b9d3a5b4ece14285f4557 CVE-2024-3883,0,0,c0ee3c129d03d9b7803729c6b8ba3c3dbf4ee4f2b39f81dd559f9f8568fb1be9,2024-05-02T13:27:25.103000 CVE-2024-3885,0,0,18d5fcf15976a3d948a4584d141049e724e0352960b62e33e0645d8a5c391224,2024-05-02T18:00:37.360000 CVE-2024-3887,0,0,798d7748b1074258e6c6a927f8fccffc602325526aac11c704efaf0a6ac77dca,2024-05-16T13:03:05.353000 +CVE-2024-3888,1,1,b85ecaa3b85ed34250738d8d4a33d3d115e06af7f28b55da528dced7cee3d022,2024-06-04T05:15:49.330000 CVE-2024-3889,0,0,c4039354ee4d81ce5faec2ce618c8f0af30c97c1ad1feeb689836cb585b438a6,2024-04-23T12:52:09.397000 CVE-2024-3890,0,0,167befe3a418fe829a07bf47548aa5d5c5fe13f91b75a3184f188bef038919b6,2024-04-26T12:58:17.720000 CVE-2024-3891,0,0,8daff08d10085680eb7790a9a2c0ef842bf636f7de8dcdfbf7cd60ad81535ead,2024-05-02T18:00:37.360000 @@ -251978,7 +251979,7 @@ CVE-2024-4546,0,0,3d8214b19328ce0698128d2541020c31eac589ba32f1eccefac58acec39f32 CVE-2024-4547,0,0,6b600f363e41b63ee43a4b2365298fb38de96fd61b910d0724ca38ee29a8a8df,2024-05-06T16:00:59.253000 CVE-2024-4548,0,0,255fb62729cbf70b5d240d036752cc7d31677deac2357745733c1172bc76cfe7,2024-05-06T16:00:59.253000 CVE-2024-4549,0,0,6f08cdb7bdf1bc14a6d26c3a39b799558e43e67fec9cb01e1f3b74f80a87ace3,2024-05-06T21:15:48.783000 -CVE-2024-4552,1,1,43d53095ae4a7a8b114d7054e78ad5c73bd9dca3b45b6d17e6b4fecdfff25711,2024-06-04T02:15:49.417000 +CVE-2024-4552,0,0,43d53095ae4a7a8b114d7054e78ad5c73bd9dca3b45b6d17e6b4fecdfff25711,2024-06-04T02:15:49.417000 CVE-2024-4553,0,0,8b88b932112e5db46be28f06635e2ec7d2585d5bcb10d64401d792f4b888b1c3,2024-05-21T12:37:59.687000 CVE-2024-4558,0,0,53052249d37fc7466ecbaee9075a2de9dd82580681c41021781e6c264c5e18ad,2024-05-07T20:07:58.737000 CVE-2024-4559,0,0,04253977f1b3aac9c2c8228f67b55a5d97f0f228a3fd1b3fdffeaf9dbbc176fb,2024-05-07T20:07:58.737000 @@ -252173,7 +252174,7 @@ CVE-2024-4858,0,0,7e6f62031377207832745d7baec775cb8f5592ecc9e1490c12da872c1b62dd CVE-2024-4859,0,0,3de5434b35db9344c6a8c9ff1c0891dd93d801d8510e1a23be87da56d66078a2,2024-05-14T19:17:55.627000 CVE-2024-4860,0,0,078ece1acb5f59d15050f08de42942705925d025d9ef9dfb969c99e0b62152d4,2024-05-14T19:17:55.627000 CVE-2024-4865,0,0,034a7c12f3d6f4bd5ac54ee1f34abd70a559c5b9a18ae852351f79db6d61b9c9,2024-05-20T13:00:34.807000 -CVE-2024-4870,1,1,d6adbae3a2deaa06a84f4ab8071fd04c6126b1fba472a92aa057add1178841c4,2024-06-04T02:15:49.620000 +CVE-2024-4870,0,0,d6adbae3a2deaa06a84f4ab8071fd04c6126b1fba472a92aa057add1178841c4,2024-06-04T02:15:49.620000 CVE-2024-4871,0,0,089a89f3309c27433f20e3be4ef9a00379f9f19601c1c8029649846113aed43a,2024-05-14T19:17:55.627000 CVE-2024-4875,0,0,aa35cb89fee530b58aa987ffc67ea97738c0ba567903bf01429a1a1259923db8,2024-05-21T12:37:59.687000 CVE-2024-4876,0,0,02aac8d1be489833aa2e07f8be8ce083249ac7dc2fcc33fd144386b8d365fef2,2024-05-21T12:37:59.687000