pluck-cms / pluck

Central repo for pluck cms
http://www.pluck-cms.org
55 stars 37 forks source link

Xss & file upload vuln. Please advise. #58

Closed Bgreen7887 closed 6 years ago

Bgreen7887 commented 6 years ago

Hi do you have a email address?

BSteelooper commented 6 years ago

The issue is confirmed.

Threat level: LOW Affected: Admin panel

XSS: Not properly sanitising the output (input) fields file upload: Not blocking all executable scripts

Remediation: Updated several files. Currently under retest with issuer.

BSteelooper commented 6 years ago

Issue remediation is confirmed by s7acktrac3