changeweb / Unifiedtransform

A school management Software
https://changeweb.github.io/Unifiedtransform/
GNU General Public License v3.0
2.78k stars 1.22k forks source link

Is your email Up? #317

Closed am0o0 closed 2 years ago

am0o0 commented 2 years ago

Hey dear changeweb team. can you just check that your email with address robinmilfor870@gmail.com is working or not ? If it is Up already, can you tell me receive any message from Huntr.dev or not? with regards, Amammad.

changeweb commented 2 years ago

It works. Sorry, I have missed your email. I checked the vulnerability. Do you have any suggestion about the fix?

am0o0 commented 2 years ago

I want to send you the fix suggestions but get this error

Address not found Your message wasn't delivered to robinmilfor870@gmail.com because the address couldn't be found, or is unable to receive mail. LEARN MORE

changeweb commented 2 years ago

Oh, you made a mistake. It is robinmilford870@gmail.com not robinmilfor870@gmail.com. You missed d.

changeweb commented 2 years ago

Hi amammad, I have added a patch for this issue. Please check and let me know if this is working.

Regards, Hasib Mahmud

On Tue, Aug 10, 2021 at 6:55 PM amammad @.***> wrote:

I want to send you the fix suggestions but get this error

Address not found Your message wasn't delivered to @.*** because the address couldn't be found, or is unable to receive mail. LEARN MORE

— You are receiving this because you commented. Reply to this email directly, view it on GitHub https://github.com/changeweb/Unifiedtransform/issues/317#issuecomment-896003234, or unsubscribe https://github.com/notifications/unsubscribe-auth/ACLQC645J57LPG4ZBIWUEH3T4EOSJANCNFSM5B3Z76FA . Triage notifications on the go with GitHub Mobile for iOS https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675 or Android https://play.google.com/store/apps/details?id=com.github.android&utm_campaign=notification-email .

am0o0 commented 2 years ago

Hey man how are you today, I hope for you to be fine … I'm so sorry, yesterday I had problem and I can't answer your last question in email. Yah now this is good. also look at these reports that already have same issue in mentioned endpoints https://huntr.dev/bounties/accbf214-2183-461c-856d-f57c239bac45/ https://huntr.dev/bounties/15de56d1-69f2-43e7-be83-1706dd3553b6/ https://huntr.dev/bounties/a879969e-fcab-4d00-87e2-43f33c425fc7/ https://huntr.dev/bounties/9fe128e3-f5e7-4041-8655-c8991ab07baa/

changeweb commented 2 years ago

No problem. Thanks for pointing out other issues. I will patch them as well.

changeweb commented 2 years ago

@amammad I have pushed a commit regarding the fix of these issues. Please check and let me know if it is working.

am0o0 commented 2 years ago

Yah I saw them, just make the other GET requests to POST like /event endpoint.

changeweb commented 2 years ago

Today's commit is about those changes.

am0o0 commented 2 years ago

OK, I comment on the lines of commit that clarify what I mean.

am0o0 commented 2 years ago

Hey man How are you these days ? can I ask you to look at my new report ?