Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Several Security Issues Identified #599

Closed
jmrcsnchz opened this issue Jan 19, 2024 · 3 comments
Closed

Several Security Issues Identified #599

jmrcsnchz opened this issue Jan 19, 2024 · 3 comments

Comments

@jmrcsnchz
Copy link

[SECURITY]

Security Issues

Hi, we are a group of security consultants / researchers and we've identified a number of security issues in this project (ranging from SQL injection, XSS, to Account Privilege Escalation). We would like to disclose these vulnerabilities responsibly and we're hoping to get in touch with the repo maintainer. Please don't hesitate to reach out via my email. Thanks!

@WillyXJ
Copy link
Owner

WillyXJ commented Jan 31, 2024

Thanks for the report!

This is now fixed in fM 4.5.1 and later.

@jmrcsnchz
Copy link
Author

jmrcsnchz commented Jan 31, 2024 via email

@WillyXJ
Copy link
Owner

WillyXJ commented Jan 31, 2024

Yes, I did request CVEs for each of them. Expectations are to have assignments later this week.

@WillyXJ WillyXJ closed this as completed Feb 6, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants