From cb900eb50b9a8f07281733723477d5b7a4d3a63c Mon Sep 17 00:00:00 2001 From: cad-safe-bot Date: Sat, 9 Sep 2023 08:00:28 +0000 Subject: [PATCH] Auto-Update: 2023-09-09T08:00:24.830392+00:00 --- CVE-2023/CVE-2023-48xx/CVE-2023-4845.json | 88 +++++++++++++++++++++++ README.md | 16 ++--- 2 files changed, 94 insertions(+), 10 deletions(-) create mode 100644 CVE-2023/CVE-2023-48xx/CVE-2023-4845.json diff --git a/CVE-2023/CVE-2023-48xx/CVE-2023-4845.json b/CVE-2023/CVE-2023-48xx/CVE-2023-4845.json new file mode 100644 index 00000000000..a1a182ce0c1 --- /dev/null +++ b/CVE-2023/CVE-2023-48xx/CVE-2023-4845.json @@ -0,0 +1,88 @@ +{ + "id": "CVE-2023-4845", + "sourceIdentifier": "cna@vuldb.com", + "published": "2023-09-09T07:15:50.457", + "lastModified": "2023-09-09T07:15:50.457", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "A vulnerability was found in SourceCodester Simple Membership System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file account_edit_query.php. The manipulation of the argument admin_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-239254 is the identifier assigned to this vulnerability." + } + ], + "metrics": { + "cvssMetricV30": [ + { + "source": "cna@vuldb.com", + "type": "Secondary", + "cvssData": { + "version": "3.0", + "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "LOW", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "LOW", + "integrityImpact": "LOW", + "availabilityImpact": "LOW", + "baseScore": 6.3, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 2.8, + "impactScore": 3.4 + } + ], + "cvssMetricV2": [ + { + "source": "cna@vuldb.com", + "type": "Secondary", + "cvssData": { + "version": "2.0", + "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P", + "accessVector": "NETWORK", + "accessComplexity": "LOW", + "authentication": "SINGLE", + "confidentialityImpact": "PARTIAL", + "integrityImpact": "PARTIAL", + "availabilityImpact": "PARTIAL", + "baseScore": 6.5 + }, + "baseSeverity": "MEDIUM", + "exploitabilityScore": 8.0, + "impactScore": 6.4, + "acInsufInfo": false, + "obtainAllPrivilege": false, + "obtainUserPrivilege": false, + "obtainOtherPrivilege": false, + "userInteractionRequired": false + } + ] + }, + "weaknesses": [ + { + "source": "cna@vuldb.com", + "type": "Primary", + "description": [ + { + "lang": "en", + "value": "CWE-89" + } + ] + } + ], + "references": [ + { + "url": "https://github.com/BigBaos/MemShipVul/blob/main/Simple-Membership-System%20account_edit_query.php%20has%20Sqlinjection.pdf", + "source": "cna@vuldb.com" + }, + { + "url": "https://vuldb.com/?ctiid.239254", + "source": "cna@vuldb.com" + }, + { + "url": "https://vuldb.com/?id.239254", + "source": "cna@vuldb.com" + } + ] +} \ No newline at end of file diff --git a/README.md b/README.md index 16e73c0aba6..bbbbddb1ee4 100644 --- a/README.md +++ b/README.md @@ -9,13 +9,13 @@ Repository synchronizes with the NVD every 2 hours. ### Last Repository Update ```plain -2023-09-09T06:00:25.115917+00:00 +2023-09-09T08:00:24.830392+00:00 ``` ### Most recent CVE Modification Timestamp synchronized with NVD ```plain -2023-09-09T04:15:10.657000+00:00 +2023-09-09T07:15:50.457000+00:00 ``` ### Last Data Feed Release @@ -29,24 +29,20 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/ ### Total Number of included CVEs ```plain -224542 +224543 ``` ### CVEs added in the last Commit -Recently added CVEs: `0` +Recently added CVEs: `1` +* [CVE-2023-4845](CVE-2023/CVE-2023-48xx/CVE-2023-4845.json) (`2023-09-09T07:15:50.457`) ### CVEs modified in the last Commit -Recently modified CVEs: `5` +Recently modified CVEs: `0` -* [CVE-2022-45061](CVE-2022/CVE-2022-450xx/CVE-2022-45061.json) (`2023-09-09T04:15:09.937`) -* [CVE-2023-2906](CVE-2023/CVE-2023-29xx/CVE-2023-2906.json) (`2023-09-09T04:15:10.243`) -* [CVE-2023-4511](CVE-2023/CVE-2023-45xx/CVE-2023-4511.json) (`2023-09-09T04:15:10.367`) -* [CVE-2023-4512](CVE-2023/CVE-2023-45xx/CVE-2023-4512.json) (`2023-09-09T04:15:10.540`) -* [CVE-2023-4513](CVE-2023/CVE-2023-45xx/CVE-2023-4513.json) (`2023-09-09T04:15:10.657`) ## Download and Usage