Skip to content

Commit

Permalink
2 changes (0 new | 2 updated):
Browse files Browse the repository at this point in the history
      - 0 new CVEs:
      - 2 updated CVEs: CVE-2023-4308, CVE-2024-52612
  • Loading branch information
cvelistV5 Github Action committed Feb 11, 2025
1 parent 570868d commit d66f219
Show file tree
Hide file tree
Showing 2 changed files with 17 additions and 6 deletions.
16 changes: 12 additions & 4 deletions cves/2023/4xxx/CVE-2023-4308.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,14 +8,14 @@
"assignerShortName": "Wordfence",
"dateReserved": "2023-08-11T13:32:32.860Z",
"datePublished": "2023-08-15T07:32:37.094Z",
"dateUpdated": "2025-02-05T19:36:03.596Z"
"dateUpdated": "2025-02-11T21:59:56.173Z"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence",
"dateUpdated": "2023-08-15T07:32:37.094Z"
"dateUpdated": "2025-02-11T21:59:56.173Z"
},
"affected": [
{
Expand All @@ -38,6 +38,7 @@
"value": "The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user-submitted-content’ parameter in versions up to, and including, 20230809 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."
}
],
"title": "User Submitted Posts <= 20230809 - Unauthenticated Stored Cross-Site Scripting via 'user-submitted-content'",
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3bb4d37c-c4c2-4523-9b4e-73ffb7be81ea?source=cve"
Expand All @@ -51,7 +52,9 @@
"descriptions": [
{
"lang": "en",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
"cweId": "CWE-79",
"type": "CWE"
}
]
}
Expand All @@ -70,7 +73,12 @@
{
"lang": "en",
"type": "finder",
"value": "NGÔ THIÊN AN"
"value": "Ngô Thiên An"
},
{
"lang": "en",
"type": "finder",
"value": "Phan Trong Quan"
}
],
"timeline": [
Expand Down
7 changes: 5 additions & 2 deletions cves/2024/52xxx/CVE-2024-52612.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
"assignerShortName": "SolarWinds",
"dateReserved": "2024-11-14T20:40:33.287Z",
"datePublished": "2025-02-11T07:21:17.835Z",
"dateUpdated": "2025-02-11T15:09:18.974Z"
"dateUpdated": "2025-02-11T22:03:07.928Z"
},
"containers": {
"cna": {
Expand Down Expand Up @@ -93,11 +93,14 @@
"providerMetadata": {
"orgId": "49f11609-934d-4621-84e6-e02e032104d6",
"shortName": "SolarWinds",
"dateUpdated": "2025-02-11T07:21:17.835Z"
"dateUpdated": "2025-02-11T22:03:07.928Z"
},
"references": [
{
"url": "https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2025-1_release_notes.htm"
},
{
"url": "https://www.solarwinds.com/trust-center/security-advisories/cve-2024-52612"
}
],
"solutions": [
Expand Down

0 comments on commit d66f219

Please sign in to comment.