René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

139 lines
4.8 KiB
JSON

{
"id": "CVE-2022-24374",
"sourceIdentifier": "vultures@jpcert.or.jp",
"published": "2022-02-24T15:15:29.287",
"lastModified": "2022-03-02T16:32:56.867",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors. This vulnerability is different from CVE-2022-23916."
},
{
"lang": "es",
"value": "Una vulnerabilidad de tipo Cross-site scripting en a-blog cms versiones Ver.2.8.x series anteriores a Ver.2.8.75, versiones Ver.2.9.x series anteriores a Ver.2.9.40, versiones Ver.2.10.x series anteriores a Ver.2.10.44, versiones Ver.2.11.x series anteriores a Ver.2.11.42 y versiones Ver.3.0.x series anteriores a Ver.3.0.1, permite a un atacante remoto autenticado inyectar un script arbitrario por medio de vectores no especificados. Esta vulnerabilidad es diferente de CVE-2022-23916"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 6.1,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.8,
"impactScore": 2.7
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*",
"versionStartIncluding": "2.8.0",
"versionEndExcluding": "2.8.75",
"matchCriteriaId": "9F010318-C88D-4F0D-9648-CD8CEE015D3B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*",
"versionStartIncluding": "2.9.0",
"versionEndExcluding": "2.9.40",
"matchCriteriaId": "A0320EBA-DACA-4E38-AAF7-BFB93414BECC"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*",
"versionStartIncluding": "2.10.0",
"versionEndExcluding": "2.10.44",
"matchCriteriaId": "3D0763C8-A9C0-4A27-B4DF-456C4AF75D82"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*",
"versionStartIncluding": "2.11.0",
"versionEndExcluding": "2.11.42",
"matchCriteriaId": "C92C05DD-EF1E-4CD2-9F4A-846DBC2C89A0"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:appleple:a-blog_cms:3.0.0:*:*:*:*:*:*:*",
"matchCriteriaId": "521E93AF-17C4-4AB0-9FDA-9C997E74608A"
}
]
}
]
}
],
"references": [
{
"url": "https://developer.a-blogcms.jp/blog/news/security-202202.html",
"source": "vultures@jpcert.or.jp",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://jvn.jp/en/jp/JVN14706307/index.html",
"source": "vultures@jpcert.or.jp",
"tags": [
"Third Party Advisory"
]
}
]
}