i7MEDIA / mojoportal

mojoPortal is an extensible, cross database, mobile friendly, web content management system (CMS) and web application framework written in C# ASP.NET.
https://www.mojoportal.com
Other
197 stars 100 forks source link

Report Security Bug Using Demo #240

Closed H3c-t0r closed 3 months ago

H3c-t0r commented 3 months ago

Hello Team,

Just wanted to know if the Demo is the latest version of Mojoportal and can be used to report security Vulnerability?

H3c-t0r commented 3 months ago

any updates ?

JosephMDavis commented 3 months ago

Hi @graphyhiren,

The demo site is not the latest version of mojoPortal. We're fixing that today.

If you know of a vulnerability, please report it on the mojoPortal website.

My apologies for not answering sooner. Monday was a national holiday for us.

H3c-t0r commented 3 months ago

Sure,

Please let me know once the demo is update to latest version and i will reconfirm the vulnerability if it exists in latest version as well and will submit the vulnerability report. Due some issue i am not able to deploy the mojo in my local system so i have checked it on demo.

JosephMDavis commented 3 months ago

Please go ahead and submit your findings here.

H3c-t0r commented 3 months ago

Hello,

It seems there is some issue with submit vulnerability button. It is stuck on Please wait and nothing happens. Could you please check.

JosephMDavis commented 3 months ago

Sorry about that, looks like we're testing a new feature on the mojo site and it has an issue, please email the report to support (at) i7media.net

H3c-t0r commented 3 months ago

Hello @JosephMDavis

Just sent the email with the vulnerability details. Please let me know incase anything required form my end.

Thank you.

H3c-t0r commented 3 months ago

Hello,

Just for the confirmation if you have received the vulnerability report and is being processed ?

JosephMDavis commented 3 months ago

Yes, we have received the report.

H3c-t0r commented 3 months ago

Hello @JosephMDavis

Any updates on the report ? also could you please let me know if the vulnerability is applicable for CVE once the issue is resolved.