diff --git a/CVE-2024/CVE-2024-23xx/CVE-2024-2333.json b/CVE-2024/CVE-2024-23xx/CVE-2024-2333.json new file mode 100644 index 00000000000..adcbc7c55bc --- /dev/null +++ b/CVE-2024/CVE-2024-23xx/CVE-2024-2333.json @@ -0,0 +1,88 @@ +{ + "id": "CVE-2024-2333", + "sourceIdentifier": "cna@vuldb.com", + "published": "2024-03-09T16:15:42.790", + "lastModified": "2024-03-09T16:15:42.790", + "vulnStatus": "Received", + "descriptions": [ + { + "lang": "en", + "value": "A vulnerability classified as critical has been found in CodeAstro Membership Management System 1.0. Affected is an unknown function of the file /add_members.php. The manipulation of the argument fullname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-256284." + } + ], + "metrics": { + "cvssMetricV31": [ + { + "source": "cna@vuldb.com", + "type": "Secondary", + "cvssData": { + "version": "3.1", + "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", + "attackVector": "NETWORK", + "attackComplexity": "LOW", + "privilegesRequired": "LOW", + "userInteraction": "NONE", + "scope": "UNCHANGED", + "confidentialityImpact": "LOW", + "integrityImpact": "LOW", + "availabilityImpact": "LOW", + "baseScore": 6.3, + "baseSeverity": "MEDIUM" + }, + "exploitabilityScore": 2.8, + "impactScore": 3.4 + } + ], + "cvssMetricV2": [ + { + "source": "cna@vuldb.com", + "type": "Secondary", + "cvssData": { + "version": "2.0", + "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P", + "accessVector": "NETWORK", + "accessComplexity": "LOW", + "authentication": "SINGLE", + "confidentialityImpact": "PARTIAL", + "integrityImpact": "PARTIAL", + "availabilityImpact": "PARTIAL", + "baseScore": 6.5 + }, + "baseSeverity": "MEDIUM", + "exploitabilityScore": 8.0, + "impactScore": 6.4, + "acInsufInfo": false, + "obtainAllPrivilege": false, + "obtainUserPrivilege": false, + "obtainOtherPrivilege": false, + "userInteractionRequired": false + } + ] + }, + "weaknesses": [ + { + "source": "cna@vuldb.com", + "type": "Secondary", + "description": [ + { + "lang": "en", + "value": "CWE-89" + } + ] + } + ], + "references": [ + { + "url": "https://github.com/0x404Ming/CVE_Hunter/blob/main/SQLi-3.md", + "source": "cna@vuldb.com" + }, + { + "url": "https://vuldb.com/?ctiid.256284", + "source": "cna@vuldb.com" + }, + { + "url": "https://vuldb.com/?id.256284", + "source": "cna@vuldb.com" + } + ] +} \ No newline at end of file diff --git a/README.md b/README.md index ef60397898b..d3cc2dac974 100644 --- a/README.md +++ b/README.md @@ -9,13 +9,13 @@ Repository synchronizes with the NVD every 2 hours. ### Last Repository Update ```plain -2024-03-09T15:00:37.668253+00:00 +2024-03-09T17:00:37.374846+00:00 ``` ### Most recent CVE Modification Timestamp synchronized with NVD ```plain -2024-03-09T14:15:51.433000+00:00 +2024-03-09T16:15:42.790000+00:00 ``` ### Last Data Feed Release @@ -29,14 +29,14 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/ ### Total Number of included CVEs ```plain -240937 +240938 ``` ### CVEs added in the last Commit Recently added CVEs: `1` -* [CVE-2024-2332](CVE-2024/CVE-2024-23xx/CVE-2024-2332.json) (`2024-03-09T14:15:51.433`) +* [CVE-2024-2333](CVE-2024/CVE-2024-23xx/CVE-2024-2333.json) (`2024-03-09T16:15:42.790`) ### CVEs modified in the last Commit diff --git a/_state.csv b/_state.csv index b66d3570c16..fbafddae123 100644 --- a/_state.csv +++ b/_state.csv @@ -239749,7 +239749,7 @@ CVE-2024-23310,0,0,c7355a50b4bca7bc3b633f9707105f29200f0be36a2fd5cfb29df38b85890 CVE-2024-23313,0,0,ca34781688f7e9926dc7e3cf4b6af4657420b9da713475de2ea189c35b7183d1,2024-02-20T19:50:53.960000 CVE-2024-23314,0,0,b1c4a7acc71e147348da30d8a66dbeab4342e6585976e49de7252a67ae54f62d,2024-02-14T18:04:45.380000 CVE-2024-23319,0,0,6250a98d8fb4de9dc7adf992ef419352b4c640948bb204f9b6b1a6a1e471f523,2024-02-15T18:44:04.737000 -CVE-2024-2332,1,1,6e731024e268815b31bee3d3758abe3a744219521dbb4f7a5c48d6585045dcb4,2024-03-09T14:15:51.433000 +CVE-2024-2332,0,0,6e731024e268815b31bee3d3758abe3a744219521dbb4f7a5c48d6585045dcb4,2024-03-09T14:15:51.433000 CVE-2024-23320,0,0,cea4cd27104e41049e9c7232ab6062356d6701f7385c875b6bbc05863f77127b,2024-02-23T19:31:25.817000 CVE-2024-23322,0,0,efdd5208c12e6ab610c84f708ac54206d4a8e094359274c8f3041236f4686749,2024-02-15T04:48:20.247000 CVE-2024-23323,0,0,9ef57ef11998f55bee596cb29f1fbe7dc637ddbdf2aa13fe046f9f2eea8d8f88,2024-02-15T04:48:09.937000 @@ -239758,6 +239758,7 @@ CVE-2024-23325,0,0,70301add03c2e2278861270a456ddd507fac1caa8f238d4654fa7a889c063 CVE-2024-23327,0,0,23e7e171aa9435048ef128fcb499e07e85d88191467319d42823b5790591ee1c,2024-02-15T04:45:57.207000 CVE-2024-23328,0,0,65a4fb886a94e46a4951007e6f258c021362f559e9cc51e8a0d68bb7c606ace0,2024-02-29T13:49:29.390000 CVE-2024-23329,0,0,0872cee4434cd36ea6d6e070e0df43a79e4470fecf3359a8aa00c845af990886,2024-01-26T20:19:59.393000 +CVE-2024-2333,1,1,aa196248435324eca8586209e689bd91b8931dde2455a0781525d3e3f7c4b218,2024-03-09T16:15:42.790000 CVE-2024-23330,0,0,4c6f25b3798cb741ccc23b207d525fcd88994089a8ae4e38ec06ed8734c9fdae,2024-02-01T17:20:38.387000 CVE-2024-23331,0,0,28e704ef5336c7eeb7f5c6708c0676ab5e78ab6128c57db716e26b15b903c5a7,2024-01-29T15:31:57.737000 CVE-2024-23332,0,0,ad52e25a8e8aa939055f450db475e34085130355e0e6d4b9d3c88d3525604a79,2024-02-29T21:16:49.777000