-
Notifications
You must be signed in to change notification settings - Fork 104
Open
Description
It seems there are multiple cross-site request forgery (CSRF) vulnerabilities within the latest version of ViMbAdmin. Can we get a status on these fixes?
Seems the timeline states that you don't have time to fix bask in 2017, but wondering if any solution is in place now?
- 22/01/2017 : Initial discovery.
- 16/02/2017 : First contact with opensolutions.io
- 16/02/2017 : Advisory sent.
- 24/02/2017 : Reply from the owner, acknowledging the report and planning to fix the vulnerabilities.
- 13/03/2017 : Sysdream Labs request for an update.
- 29/03/2017 : Second request for an update.
- 29/03/2017 : Reply from the owner stating that he has no time to fix the issues.
- 03/05/2017 : Full disclosure.
References:
endelwar and fliphess
Metadata
Metadata
Assignees
Labels
No labels