From ced940460785d36b9334a991e33b061b4a8db498 Mon Sep 17 00:00:00 2001 From: cad-safe-bot Date: Sat, 30 Dec 2023 17:00:28 +0000 Subject: [PATCH] Auto-Update: 2023-12-30T17:00:24.420415+00:00 --- CVE-2023/CVE-2023-505xx/CVE-2023-50550.json | 20 +++++ CVE-2023/CVE-2023-505xx/CVE-2023-50578.json | 20 +++++ CVE-2023/CVE-2023-511xx/CVE-2023-51133.json | 24 ++++++ CVE-2023/CVE-2023-511xx/CVE-2023-51135.json | 24 ++++++ CVE-2023/CVE-2023-511xx/CVE-2023-51136.json | 24 ++++++ CVE-2023/CVE-2023-71xx/CVE-2023-7176.json | 88 +++++++++++++++++++++ CVE-2023/CVE-2023-71xx/CVE-2023-7177.json | 88 +++++++++++++++++++++ README.md | 16 ++-- 8 files changed, 299 insertions(+), 5 deletions(-) create mode 100644 CVE-2023/CVE-2023-505xx/CVE-2023-50550.json create mode 100644 CVE-2023/CVE-2023-505xx/CVE-2023-50578.json create mode 100644 CVE-2023/CVE-2023-511xx/CVE-2023-51133.json create mode 100644 CVE-2023/CVE-2023-511xx/CVE-2023-51135.json create mode 100644 CVE-2023/CVE-2023-511xx/CVE-2023-51136.json create mode 100644 CVE-2023/CVE-2023-71xx/CVE-2023-7176.json create mode 100644 CVE-2023/CVE-2023-71xx/CVE-2023-7177.json diff --git a/CVE-2023/CVE-2023-505xx/CVE-2023-50550.json b/CVE-2023/CVE-2023-505xx/CVE-2023-50550.json new file mode 100644 index 00000000000..99eb8515a0a --- /dev/null +++ b/CVE-2023/CVE-2023-505xx/CVE-2023-50550.json @@ -0,0 +1,20 @@ +{ + "id": "CVE-2023-50550", + "sourceIdentifier": "cve@mitre.org", + "published": "2023-12-30T16:15:44.757", + "lastModified": "2023-12-30T16:15:44.757", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "layui up to v2.74 was discovered to contain a cross-site scripting (XSS) vulnerability via the data-content parameter." + } + ], + "metrics": {}, + "references": [ + { + "url": "https://gitee.com/layui/layui/issues?utf8=%E2%9C%93&state=all&issue_search=xss", + "source": "cve@mitre.org" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-505xx/CVE-2023-50578.json b/CVE-2023/CVE-2023-505xx/CVE-2023-50578.json new file mode 100644 index 00000000000..f0c46a6cc04 --- /dev/null +++ b/CVE-2023/CVE-2023-505xx/CVE-2023-50578.json @@ -0,0 +1,20 @@ +{ + "id": "CVE-2023-50578", + "sourceIdentifier": "cve@mitre.org", + "published": "2023-12-30T16:15:44.820", + "lastModified": "2023-12-30T16:15:44.820", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do." + } + ], + "metrics": {}, + "references": [ + { + "url": "https://gitee.com/mingSoft/MCMS/issues/I8MAJK", + "source": "cve@mitre.org" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-511xx/CVE-2023-51133.json b/CVE-2023/CVE-2023-511xx/CVE-2023-51133.json new file mode 100644 index 00000000000..86abb05fb68 --- /dev/null +++ b/CVE-2023/CVE-2023-511xx/CVE-2023-51133.json @@ -0,0 +1,24 @@ +{ + "id": "CVE-2023-51133", + "sourceIdentifier": "cve@mitre.org", + "published": "2023-12-30T16:15:44.863", + "lastModified": "2023-12-30T16:15:44.863", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formRoute." + } + ], + "metrics": {}, + "references": [ + { + "url": "https://github.com/XYIYM/Digging/blob/main/TOTOLINK/X2000R/26/1.md", + "source": "cve@mitre.org" + }, + { + "url": "https://totolink.cn/home/menu/detail.html?menu_listtpl=download&id=85&ids=36", + "source": "cve@mitre.org" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-511xx/CVE-2023-51135.json b/CVE-2023/CVE-2023-511xx/CVE-2023-51135.json new file mode 100644 index 00000000000..f28a92d1e8d --- /dev/null +++ b/CVE-2023/CVE-2023-511xx/CVE-2023-51135.json @@ -0,0 +1,24 @@ +{ + "id": "CVE-2023-51135", + "sourceIdentifier": "cve@mitre.org", + "published": "2023-12-30T16:15:44.910", + "lastModified": "2023-12-30T16:15:44.910", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formPasswordSetup." + } + ], + "metrics": {}, + "references": [ + { + "url": "https://github.com/XYIYM/Digging/blob/main/TOTOLINK/X2000R/29/1.md", + "source": "cve@mitre.org" + }, + { + "url": "https://totolink.cn/home/menu/detail.html?menu_listtpl=download&id=85&ids=36", + "source": "cve@mitre.org" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-511xx/CVE-2023-51136.json b/CVE-2023/CVE-2023-511xx/CVE-2023-51136.json new file mode 100644 index 00000000000..932ee233de4 --- /dev/null +++ b/CVE-2023/CVE-2023-511xx/CVE-2023-51136.json @@ -0,0 +1,24 @@ +{ + "id": "CVE-2023-51136", + "sourceIdentifier": "cve@mitre.org", + "published": "2023-12-30T16:15:44.957", + "lastModified": "2023-12-30T16:15:44.957", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formRebootSchedule." + } + ], + "metrics": {}, + "references": [ + { + "url": "https://github.com/XYIYM/Digging/blob/main/TOTOLINK/X2000R/28/1.md", + "source": "cve@mitre.org" + }, + { + "url": "https://totolink.cn/home/menu/detail.html?menu_listtpl=download&id=85&ids=36", + "source": "cve@mitre.org" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-71xx/CVE-2023-7176.json b/CVE-2023/CVE-2023-71xx/CVE-2023-7176.json new file mode 100644 index 00000000000..b483ecb050c --- /dev/null +++ b/CVE-2023/CVE-2023-71xx/CVE-2023-7176.json @@ -0,0 +1,88 @@ +{ + "id": "CVE-2023-7176", + "sourceIdentifier": "cna@vuldb.com", + "published": "2023-12-30T16:15:45.003", + "lastModified": "2023-12-30T16:15:45.003", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "A vulnerability classified as critical has been found in Campcodes Online College Library System 1.0. This affects an unknown part of the file /admin/return_add.php of the component HTTP POST Request Handler. The manipulation of the argument student leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249363." + } + ], + "metrics": { + "cvssMetricV31": [ + { + "source": "cna@vuldb.com", + "type": "Secondary", + "cvssData": { + "version": "3.1", + "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "HIGH", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "LOW", + "integrityImpact": "LOW", + "availabilityImpact": "LOW", + "baseScore": 4.7, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 1.2, + "impactScore": 3.4 + } + ], + "cvssMetricV2": [ + { + "source": "cna@vuldb.com", + "type": "Secondary", + "cvssData": { + "version": "2.0", + "vectorString": "AV:N/AC:L/Au:M/C:P/I:P/A:P", + "accessVector": "NETWORK", + "accessComplexity": "LOW", + "authentication": "MULTIPLE", + "confidentialityImpact": "PARTIAL", + "integrityImpact": "PARTIAL", + "availabilityImpact": "PARTIAL", + "baseScore": 5.8 + }, + "baseSeverity": "MEDIUM", + "exploitabilityScore": 6.4, + "impactScore": 6.4, + "acInsufInfo": false, + "obtainAllPrivilege": false, + "obtainUserPrivilege": false, + "obtainOtherPrivilege": false, + "userInteractionRequired": false + } + ] + }, + "weaknesses": [ + { + "source": "cna@vuldb.com", + "type": "Primary", + "description": [ + { + "lang": "en", + "value": "CWE-89" + } + ] + } + ], + "references": [ + { + "url": "https://medium.com/@heishou/libsystem-foreground-sql-injection-vulnerability-3-d02f0ce78fe3", + "source": "cna@vuldb.com" + }, + { + "url": "https://vuldb.com/?ctiid.249363", + "source": "cna@vuldb.com" + }, + { + "url": "https://vuldb.com/?id.249363", + "source": "cna@vuldb.com" + } + ] +} \ No newline at end of file diff --git a/CVE-2023/CVE-2023-71xx/CVE-2023-7177.json b/CVE-2023/CVE-2023-71xx/CVE-2023-7177.json new file mode 100644 index 00000000000..768161bff67 --- /dev/null +++ b/CVE-2023/CVE-2023-71xx/CVE-2023-7177.json @@ -0,0 +1,88 @@ +{ + "id": "CVE-2023-7177", + "sourceIdentifier": "cna@vuldb.com", + "published": "2023-12-30T16:15:45.230", + "lastModified": "2023-12-30T16:15:45.230", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "A vulnerability classified as critical was found in Campcodes Online College Library System 1.0. This vulnerability affects unknown code of the file /admin/book_add.php of the component HTTP POST Request Handler. The manipulation of the argument category leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249364." + } + ], + "metrics": { + "cvssMetricV31": [ + { + "source": "cna@vuldb.com", + "type": "Secondary", + "cvssData": { + "version": "3.1", + "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "HIGH", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "LOW", + "integrityImpact": "LOW", + "availabilityImpact": "LOW", + "baseScore": 4.7, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 1.2, + "impactScore": 3.4 + } + ], + "cvssMetricV2": [ + { + "source": "cna@vuldb.com", + "type": "Secondary", + "cvssData": { + "version": "2.0", + "vectorString": "AV:N/AC:L/Au:M/C:P/I:P/A:P", + "accessVector": "NETWORK", + "accessComplexity": "LOW", + "authentication": "MULTIPLE", + "confidentialityImpact": "PARTIAL", + "integrityImpact": "PARTIAL", + "availabilityImpact": "PARTIAL", + "baseScore": 5.8 + }, + "baseSeverity": "MEDIUM", + "exploitabilityScore": 6.4, + "impactScore": 6.4, + "acInsufInfo": false, + "obtainAllPrivilege": false, + "obtainUserPrivilege": false, + "obtainOtherPrivilege": false, + "userInteractionRequired": false + } + ] + }, + "weaknesses": [ + { + "source": "cna@vuldb.com", + "type": "Primary", + "description": [ + { + "lang": "en", + "value": "CWE-89" + } + ] + } + ], + "references": [ + { + "url": "https://medium.com/@heishou/libsystem-foreground-sql-injection-vulnerability-4-cadc2983eb5e", + "source": "cna@vuldb.com" + }, + { + "url": "https://vuldb.com/?ctiid.249364", + "source": "cna@vuldb.com" + }, + { + "url": "https://vuldb.com/?id.249364", + "source": "cna@vuldb.com" + } + ] +} \ No newline at end of file diff --git a/README.md b/README.md index 96fc035d8c7..d687e621ee1 100644 --- a/README.md +++ b/README.md @@ -9,13 +9,13 @@ Repository synchronizes with the NVD every 2 hours. ### Last Repository Update ```plain -2023-12-30T15:00:24.762597+00:00 +2023-12-30T17:00:24.420415+00:00 ``` ### Most recent CVE Modification Timestamp synchronized with NVD ```plain -2023-12-30T13:15:16.097000+00:00 +2023-12-30T16:15:45.230000+00:00 ``` ### Last Data Feed Release @@ -29,14 +29,20 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/ ### Total Number of included CVEs ```plain -234553 +234560 ``` ### CVEs added in the last Commit -Recently added CVEs: `1` +Recently added CVEs: `7` -* [CVE-2023-7175](CVE-2023/CVE-2023-71xx/CVE-2023-7175.json) (`2023-12-30T13:15:16.097`) +* [CVE-2023-50550](CVE-2023/CVE-2023-505xx/CVE-2023-50550.json) (`2023-12-30T16:15:44.757`) +* [CVE-2023-50578](CVE-2023/CVE-2023-505xx/CVE-2023-50578.json) (`2023-12-30T16:15:44.820`) +* [CVE-2023-51133](CVE-2023/CVE-2023-511xx/CVE-2023-51133.json) (`2023-12-30T16:15:44.863`) +* [CVE-2023-51135](CVE-2023/CVE-2023-511xx/CVE-2023-51135.json) (`2023-12-30T16:15:44.910`) +* [CVE-2023-51136](CVE-2023/CVE-2023-511xx/CVE-2023-51136.json) (`2023-12-30T16:15:44.957`) +* [CVE-2023-7176](CVE-2023/CVE-2023-71xx/CVE-2023-7176.json) (`2023-12-30T16:15:45.003`) +* [CVE-2023-7177](CVE-2023/CVE-2023-71xx/CVE-2023-7177.json) (`2023-12-30T16:15:45.230`) ### CVEs modified in the last Commit