gugoan / economizzer

Open Source Personal Finance Manager
http://www.economizzer.org/
MIT License
464 stars 117 forks source link

Trying to get in touch regarding a security issue #144

Closed JamieSlome closed 2 years ago

JamieSlome commented 3 years ago

Hey there!

I'd like to report a security issue but cannot find contact instructions on your repository.

If not a hassle, might you kindly add a SECURITY.md file with an email, or another contact method? GitHub recommends this best practice to ensure security issues are responsibly disclosed, and it would serve as a simple instruction for security researchers in the future.

Thank you for your consideration, and I look forward to hearing from you!

(cc @huntr-helper)

JamieSlome commented 2 years ago

@gugoan - just to provide fair warning that all three reports will be made public in 4 days if we do not hear back from you, as > 90 days have elapsed since disclosure.

Please get in touch if you have any questions! 👍

gugoan commented 2 years ago

Hi @JamieSlome , sorry for the delay.

I did as requested and updated several parts of the application. I will resume and follow up more often. Thanks

JamieSlome commented 2 years ago

Hello @gugoan - thanks for getting back to me.

You should have received three e-mails for various reports, but just for reference, they can be found here:

https://huntr.dev/bounties/e60841fb-5637-44c3-b16b-b4fde180c498/ https://huntr.dev/bounties/ffb23c90-c447-402f-ba5d-6813e00e4a7f/ https://huntr.dev/bounties/e3e855cf-35a0-474f-b24b-4dfbc47d5eaf/

All three are private and only accessible to you! Let me know if you have any questions 👍