inoerp / inoERP

inoERP is an OneApp [ Go back-end & Flutter front-end ] based enterprise management system
http://docs.inoerp.com/
Mozilla Public License 2.0
767 stars 675 forks source link

Multiple vulnerabilities #76

Closed fgeek closed 7 years ago

fgeek commented 7 years ago

inoERP issues

inoerp commented 7 years ago

Stop spamming here. If you have any issue then write it down in details don't put any link to advertise any site

fgeek commented 7 years ago

It was not a spam. The link is archive for well known mailing list for security discussion (oss-security) and the link contained three probably unfixed security vulnerabilities. The link does not even seem to have any advertisements. I was just worried about your users security. According to the advisory they have tried to contact inoERP many times:

2017-01-25  Issue discovered
2017-01-26  Vendor contacted -> no response
2017-02-20  Vendor contacted again -> no response
2017-03-06  Vendor contacted again -> no response
2017-03-27  Advisory Release
inoerp commented 7 years ago

No worries. We will work on them.

inoerp commented 7 years ago

All these issues have been resolved and committed