Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Question about two vulnerabilities in WebCalendar v1.2.7 #382

Open
fgeek opened this issue Jul 29, 2023 · 1 comment
Open

Question about two vulnerabilities in WebCalendar v1.2.7 #382

fgeek opened this issue Jul 29, 2023 · 1 comment

Comments

@fgeek
Copy link

fgeek commented Jul 29, 2023

Hello,

Can you tell me in which version these vulnerabilities has been fixed, thanks?

http://hyp3rlinx.altervista.org/advisories/WEBCALENDAR-V1.2.7-PHP-CODE-INJECTION.txt
http://hyp3rlinx.altervista.org/advisories/WEBCALENDAR-V1.2.7-CSRF-PROTECTION-BYPASS.txt

I am adding detection for these to https://github.com/fgeek/pyfiscan security scanner (works locally).

@craigk5n
Copy link
Owner

The second one is fixed as of v1.9.8.
Not sure on the first one.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants