Bounty upload (10/08)#245
Conversation
Mik317
left a comment
There was a problem hiding this comment.
I wasn't able to validate all the disclosures:
many of them are valid 😄 while some other ain't.
There are some disclosure I wasn't able to verify due to problems in running the software/module/tool which weren't enough documented to overcome 'em, like in web-debug (returned a strange error on prototype ...).
In those cases, I watched at the opened PR/issues and the date of the latest commits/version , which helped a lot in understanding if defensive measures have been implemented after the original reporter had shown the issue 😄
Cheers,
Mik
|
Thanks for the verification & comments there @Mik317 - I've added these to the Pull Request comment as a reference and will make changes today as per your recommendations. Much appreciated, |
Mik317
left a comment
There was a problem hiding this comment.
Froala has been patched (checked directly on the latest version) removing events and unsafe tags.
Redactor3 is vulnerable (website with editor still has a XSS issue)
Cheers,
Mik
NPM:
Mik317Mik317Mik317Mik317&mufeedvhMik317Mik317Packagist:
Mik317Mik317Mik317&mufeedvhMik317Pip:
Mik317Mik317Removed due to being invalid:
C++is currently an unsupported codebase anyway