Auto-Update: 2023-12-30T17:00:24.420415+00:00

This commit is contained in:
cad-safe-bot 2023-12-30 17:00:28 +00:00
parent 5deb25bd7b
commit ced9404607
8 changed files with 299 additions and 5 deletions

View File

@ -0,0 +1,20 @@
{
"id": "CVE-2023-50550",
"sourceIdentifier": "cve@mitre.org",
"published": "2023-12-30T16:15:44.757",
"lastModified": "2023-12-30T16:15:44.757",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "layui up to v2.74 was discovered to contain a cross-site scripting (XSS) vulnerability via the data-content parameter."
}
],
"metrics": {},
"references": [
{
"url": "https://gitee.com/layui/layui/issues?utf8=%E2%9C%93&state=all&issue_search=xss",
"source": "cve@mitre.org"
}
]
}

View File

@ -0,0 +1,20 @@
{
"id": "CVE-2023-50578",
"sourceIdentifier": "cve@mitre.org",
"published": "2023-12-30T16:15:44.820",
"lastModified": "2023-12-30T16:15:44.820",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do."
}
],
"metrics": {},
"references": [
{
"url": "https://gitee.com/mingSoft/MCMS/issues/I8MAJK",
"source": "cve@mitre.org"
}
]
}

View File

@ -0,0 +1,24 @@
{
"id": "CVE-2023-51133",
"sourceIdentifier": "cve@mitre.org",
"published": "2023-12-30T16:15:44.863",
"lastModified": "2023-12-30T16:15:44.863",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formRoute."
}
],
"metrics": {},
"references": [
{
"url": "https://github.com/XYIYM/Digging/blob/main/TOTOLINK/X2000R/26/1.md",
"source": "cve@mitre.org"
},
{
"url": "https://totolink.cn/home/menu/detail.html?menu_listtpl=download&id=85&ids=36",
"source": "cve@mitre.org"
}
]
}

View File

@ -0,0 +1,24 @@
{
"id": "CVE-2023-51135",
"sourceIdentifier": "cve@mitre.org",
"published": "2023-12-30T16:15:44.910",
"lastModified": "2023-12-30T16:15:44.910",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formPasswordSetup."
}
],
"metrics": {},
"references": [
{
"url": "https://github.com/XYIYM/Digging/blob/main/TOTOLINK/X2000R/29/1.md",
"source": "cve@mitre.org"
},
{
"url": "https://totolink.cn/home/menu/detail.html?menu_listtpl=download&id=85&ids=36",
"source": "cve@mitre.org"
}
]
}

View File

@ -0,0 +1,24 @@
{
"id": "CVE-2023-51136",
"sourceIdentifier": "cve@mitre.org",
"published": "2023-12-30T16:15:44.957",
"lastModified": "2023-12-30T16:15:44.957",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formRebootSchedule."
}
],
"metrics": {},
"references": [
{
"url": "https://github.com/XYIYM/Digging/blob/main/TOTOLINK/X2000R/28/1.md",
"source": "cve@mitre.org"
},
{
"url": "https://totolink.cn/home/menu/detail.html?menu_listtpl=download&id=85&ids=36",
"source": "cve@mitre.org"
}
]
}

View File

@ -0,0 +1,88 @@
{
"id": "CVE-2023-7176",
"sourceIdentifier": "cna@vuldb.com",
"published": "2023-12-30T16:15:45.003",
"lastModified": "2023-12-30T16:15:45.003",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "A vulnerability classified as critical has been found in Campcodes Online College Library System 1.0. This affects an unknown part of the file /admin/return_add.php of the component HTTP POST Request Handler. The manipulation of the argument student leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249363."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "LOW",
"baseScore": 4.7,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 1.2,
"impactScore": 3.4
}
],
"cvssMetricV2": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:M/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "MULTIPLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 5.8
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 6.4,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "cna@vuldb.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"references": [
{
"url": "https://medium.com/@heishou/libsystem-foreground-sql-injection-vulnerability-3-d02f0ce78fe3",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?ctiid.249363",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?id.249363",
"source": "cna@vuldb.com"
}
]
}

View File

@ -0,0 +1,88 @@
{
"id": "CVE-2023-7177",
"sourceIdentifier": "cna@vuldb.com",
"published": "2023-12-30T16:15:45.230",
"lastModified": "2023-12-30T16:15:45.230",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "A vulnerability classified as critical was found in Campcodes Online College Library System 1.0. This vulnerability affects unknown code of the file /admin/book_add.php of the component HTTP POST Request Handler. The manipulation of the argument category leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249364."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "LOW",
"baseScore": 4.7,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 1.2,
"impactScore": 3.4
}
],
"cvssMetricV2": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:M/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "MULTIPLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 5.8
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 6.4,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "cna@vuldb.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"references": [
{
"url": "https://medium.com/@heishou/libsystem-foreground-sql-injection-vulnerability-4-cadc2983eb5e",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?ctiid.249364",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?id.249364",
"source": "cna@vuldb.com"
}
]
}

View File

@ -9,13 +9,13 @@ Repository synchronizes with the NVD every 2 hours.
### Last Repository Update
```plain
2023-12-30T15:00:24.762597+00:00
2023-12-30T17:00:24.420415+00:00
```
### Most recent CVE Modification Timestamp synchronized with NVD
```plain
2023-12-30T13:15:16.097000+00:00
2023-12-30T16:15:45.230000+00:00
```
### Last Data Feed Release
@ -29,14 +29,20 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/
### Total Number of included CVEs
```plain
234553
234560
```
### CVEs added in the last Commit
Recently added CVEs: `1`
Recently added CVEs: `7`
* [CVE-2023-7175](CVE-2023/CVE-2023-71xx/CVE-2023-7175.json) (`2023-12-30T13:15:16.097`)
* [CVE-2023-50550](CVE-2023/CVE-2023-505xx/CVE-2023-50550.json) (`2023-12-30T16:15:44.757`)
* [CVE-2023-50578](CVE-2023/CVE-2023-505xx/CVE-2023-50578.json) (`2023-12-30T16:15:44.820`)
* [CVE-2023-51133](CVE-2023/CVE-2023-511xx/CVE-2023-51133.json) (`2023-12-30T16:15:44.863`)
* [CVE-2023-51135](CVE-2023/CVE-2023-511xx/CVE-2023-51135.json) (`2023-12-30T16:15:44.910`)
* [CVE-2023-51136](CVE-2023/CVE-2023-511xx/CVE-2023-51136.json) (`2023-12-30T16:15:44.957`)
* [CVE-2023-7176](CVE-2023/CVE-2023-71xx/CVE-2023-7176.json) (`2023-12-30T16:15:45.003`)
* [CVE-2023-7177](CVE-2023/CVE-2023-71xx/CVE-2023-7177.json) (`2023-12-30T16:15:45.230`)
### CVEs modified in the last Commit