Hello,
I have made a github vulnerability report and sent an email regarding a stored XSS vulnerability I discovered in this project. Please check for emails from [email protected]
Hello,
I have made a github vulnerability report and sent an email regarding a stored XSS vulnerability I discovered in this project. Please check for emails from [email protected]
Hi Henry
Seen the vulnerability report that pointed out the affected version <= 0.9
Will patch soon this week.
Thank you for detecting this.
Hello,
Thank you for working on this. Just to be clear, I put <=0.9 because that is the most recent fully released version. I did not test your 1.0 alpha release but if it handles uploads in the same manner it has the same vulnerability.
Once you publish the vulnerability, could you please request a CVE from Github? It will help me out a lot.
Thanks,
Thank you Phuong.
Hello Phuong. Can I help at all with getting a patch for this? I would like to ensure you have any help you need getting this fixed. I would be happy to create a private fork and PR to fix the vulnerability.
That would be great Henry
A pull request has been made on the NotrinosERP-ghsa-xcrc-489h-w4pv private fork which fixes the vulnerability. Please review and merge.
https://github.com/notrinos/NotrinosERP-ghsa-xcrc-489h-w4pv/pull/1
Merged and Published. Thank you Henry
Happy to be of service! You have been a pleasure to work with, thank you.
Guest browsing is open, but posting still requires a standalone forum account.
Login