Closed kushkira closed 2 months ago
sure!
Please setup your security page so that i can report it from there.
Just for your reference, you can setup the security policy with this link. https://docs.github.com/en/code-security/getting-started/adding-a-security-policy-to-your-repository
it is + Private vulnerability reporting is enabled
I found SQL Injection bug on id parameter. Below is the steps to reproduce.
Let me know if anything is required.
The code goes by and you can find the it here https://github.com/TimGeyssens/UIOMatic/blob/59f7e39b0536b8d499053b8728f363e78967c875/src/UIOMatic/wwwroot/backoffice/resources/uioMaticObject.resource.js#L104
Hey @TimGeyssens
Any update on this?
yes seem a solid vulnerability, so verified! But I am not actively working on the project.
So feel free to make a PR to fix this...
The vulnerability can only be exploited with backend access...
I was hoping to get a CVE for this.
Hey Tim Geyssens,
i happen to found a vulnerability in UIOMatic, mind to create a security page so that i can report it here.