Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerabilities [VvvebJs] #339

Closed
joaoviictorti opened this issue Feb 16, 2024 · 2 comments
Closed

Vulnerabilities [VvvebJs] #339

joaoviictorti opened this issue Feb 16, 2024 · 2 comments

Comments

@joaoviictorti
Copy link

Hi guys, how are you?

My name is João Victor, I'm a security researcher and I was doing some research on your applications. Recently, I discovered some critical flaws in the VVEBJS application, including File Upload vulnerabilities that can lead to Remote Code Execution, Directory Traversal and SSRF. These flaws were considered serious enough to be registered as CVEs by Mitre. They are currently reserved, which is why I'm contacting you first to demonstrate them in practice so that you can fix them. I can't show them here, as it's not a suitable way because it's public, I believe the most ethical way would be by email.

@givanz
Copy link
Owner

givanz commented Feb 18, 2024

Hi João Victor,

Thank you for testing and reporting vulnerabilities.
Please send the information to the email address from my profile page.

@joaoviictorti
Copy link
Author

Hello, Givanz!

Thank you for your reply. I've sent you an email detailing each step that was carried out by the faults and what each one is!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants