dmpop / pellicola

Pastebin for your photos
https://tinyvps.xyz/pellicola
GNU General Public License v3.0
165 stars 16 forks source link

:shield: Security vulnerabilities #30

Closed hitisec closed 3 years ago

hitisec commented 3 years ago

Hi, Some potential security vulnerabilities has been identified in this repository. Please Validate reports submitted on huntr and if are valid please mark them valid there. The report links are the following:

https://huntr.dev/bounties/463f99c5-2f1f-401d-8373-1b47a9a0834b/ https://huntr.dev/bounties/ceebf0a3-f278-44d5-b13d-58df0f5d4fd8/ https://huntr.dev/bounties/a6ef997e-47bd-4e1f-8615-f229f2c758f8/ https://huntr.dev/bounties/96197492-bf7c-4e0d-aab0-e80f28f992dc/ https://huntr.dev/bounties/431e8426-2f4e-40d4-b930-b01e6d448628/ https://huntr.dev/bounties/c132be19-e6b2-4c76-83a0-1d13d2d9cb79/

dmpop commented 3 years ago

Most of the reported vulnerabilities are fixed in 1052ae3942fb98cb66e3b8d54ba14e878012de88

hitisec commented 3 years ago

Can you please validate them in the site?

iohehe commented 2 years ago

Hello, I think using htmlentities() to fix this issue is safer than strip_tags() :)

dmpop commented 2 years ago

Good point! Fixed in e05feaf5fd1b1ce7000b4e5f27376564661778b8

Thank you for your tip!