Skip to content

Security: critical vulnerability in file manager upload handler - requesting private contact #20

Description

@kta1kri

I found a critical security vulnerability in the file manager's upload handler that allows cross-tenant file writes (potential RCE against other customers' websites). There's no SECURITY.md or GitHub private vulnerability reporting on this repo, so I'm not posting technical details here.

I've emailed contact@crivion.com with the full write-up. If that's not the right address, could you point me to a private channel (email, GHSA collaborator invite, etc.)? Happy to wait for a fix before any detail becomes public.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions