instantsoft / icms2

Self-hosted Site Management System
https://instantcms.ru
GNU General Public License v2.0
292 stars 119 forks source link

Security Vulnerability #1490

Closed u32i closed 5 months ago

u32i commented 5 months ago

HI,

i'm trying to report a security vulnerability by sending an email to fuze@instantcms.ru but the mail server is rejecting my email, perhaps you can enable github security advisories ? so i can report it

fuzegit commented 5 months ago

Hi, The mail server works correctly if you send an email from a valid email server.

u32i commented 5 months ago

iam sending an email from u32i@proton.me and its not delivered

fuzegit commented 5 months ago

I get notifications from github. The mail server is working.

Выделение_005

u32i commented 5 months ago

Screenshot_2024-01-30_10-32-42

fuzegit commented 5 months ago

For some reason, the server considers your email to be spam. Probably because of the domain.

u32i commented 5 months ago

any other email to contact you on ? the other email specified in the security policy also does not work, it says "upstream error"

fuzegit commented 5 months ago

Why on huntr can't you add a report?

u32i commented 5 months ago

they changed their targets back in November, they now target AI/ML projects only.

u32i commented 5 months ago

if you enabled github advisories it will be better than email

https://docs.github.com/en/code-security/security-advisories/working-with-repository-security-advisories/about-repository-security-advisories

fuzegit commented 5 months ago

if you enabled github advisories it will be better than email

Security advisories enabled