Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Notice: Deadline Submission #6138

Open
dwisiswant0 opened this issue Jan 20, 2023 · 6 comments
Open

Security Notice: Deadline Submission #6138

dwisiswant0 opened this issue Jan 20, 2023 · 6 comments
Labels

Comments

@dwisiswant0
Copy link

Hi CRM team,

I reported a vulnerability through the huntr platform and I believe that the huntr team has forwarded it to the official channel on the security policy page.

We understand that addressing vulnerabilities takes time and effort, but we haven't received any updates from the CRM team since 148 days ago. Can you please provide an explanation for the delay?

If we do not receive a response within the next week, we will be releasing a related advisory.

Maintainers with write access can view the submission by clicking on the following link:
https://huntr.dev/bounties/0ae3bbec-4a4f-41a6-8893-d40f3a838930/

Best!
Dwi

@github-actions
Copy link
Contributor

This issue is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 5 days.

@github-actions github-actions bot added the Stale label Oct 29, 2023
Copy link
Contributor

This issue was closed because it has been stalled for 15 days with no activity.

@github-actions github-actions bot closed this as not planned Won't fix, can't repro, duplicate, stale Nov 13, 2023
@DAcodedBEAT DAcodedBEAT reopened this Jan 17, 2024
@github-actions github-actions bot removed the Stale label Jan 18, 2024
Copy link
Contributor

This issue is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 5 days.

@github-actions github-actions bot added the Stale label Feb 18, 2024
Copy link
Contributor

github-actions bot commented Mar 4, 2024

This issue was closed because it has been stalled for 15 days with no activity.

@github-actions github-actions bot closed this as not planned Won't fix, can't repro, duplicate, stale Mar 4, 2024
@DAcodedBEAT
Copy link
Contributor

From the URL in case it goes away:

Reflected XSS at Cart View in churchcrm/crm
Pending
Reported on Aug 25th 2022

Description

ChurchCRM prior to version <= 4.4.5 is vulnerable to cross-site scripting specifically at the cart view under dashboard. iCount parameter does not neutralize and is placed in output that is used as a record count information.

Proof of Concept

Log in to dashboard http://HOST/session/begin.
Navigate to http://HOST/v2/cart?Message=aMessage&iCount=%3Cscript%3Ealert(document.cookie)%3C/script%3E%3C!--.

Impact

The attacker could transfer private information, such as cookies that may include session information, from the victim's machine to the attacker, and an attacker could send malicious requests on behalf of the victim, which could be especially dangerous to the site if the victim has administrator privileges to manage that site.

Occurrences

cartempty.php L15

@DAcodedBEAT DAcodedBEAT reopened this Sep 6, 2024
@DAcodedBEAT DAcodedBEAT added Security and removed Stale labels Sep 6, 2024
Copy link
Contributor

github-actions bot commented Oct 7, 2024

This issue is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 5 days.

@github-actions github-actions bot added the Stale label Oct 7, 2024
@DAcodedBEAT DAcodedBEAT removed the Stale label Oct 8, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants