-
Notifications
You must be signed in to change notification settings - Fork 66
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Insecure demo file disclosure #3260
Comments
Maybe we should report that at the vendor projects so they can provide a central fix? |
Yes we can report that, but I'm afraid not all vendors cares about it. |
We could possibly block access to these files using the |
|
Added a fix for the first one in #3261 |
Reported to vendor here: vakata/jstree#1651 |
Unauthorized file manipulation -
/vendor/vakata/jstree/demo/filebrowser/index.php
http://zikula.org/vendor/vakata/jstree/demo/filebrowser/
Possible unauthorized SSRF -
/javascript/js-webshim/dev/shims/FlashCanvasPro/proxy.php
Please make a review.
The text was updated successfully, but these errors were encountered: