-
-
Notifications
You must be signed in to change notification settings - Fork 89
Bounty upload (10/08) #245
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Mik317
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I wasn't able to validate all the disclosures:
many of them are valid 😄 while some other ain't.
There are some disclosure I wasn't able to verify due to problems in running the software/module/tool which weren't enough documented to overcome 'em, like in web-debug (returned a strange error on prototype ...).
In those cases, I watched at the opened PR/issues and the date of the latest commits/version , which helped a lot in understanding if defensive measures have been implemented after the original reporter had shown the issue 😄
Cheers,
Mik
|
Thanks for the verification & comments there @Mik317 - I've added these to the Pull Request comment as a reference and will make changes today as per your recommendations. Much appreciated, |
Mik317
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Froala has been patched (checked directly on the latest version) removing events and unsafe tags.
Redactor3 is vulnerable (website with editor still has a XSS issue)
Cheers,
Mik
NPM:
Mik317Mik317Mik317Mik317&mufeedvhMik317Mik317Packagist:
Mik317Mik317Mik317&mufeedvhMik317Pip:
Mik317Mik317Removed due to being invalid:
C++is currently an unsupported codebase anyway