[Sécurité / Security] XSS Vulnerability Report - Contacting Core Developers
Hello,
I have identified an XSS security vulnerability affecting PluXml 5.8.22. I sent two emails with the full PoC and details, but haven't received a response yet.
To adhere to responsible disclosure practices, I am not sharing the vulnerability details publicly here. Could a core maintainer please reach out via Private Message (PM) or provide a direct email address to proceed?
Best regards,
@bazooka07
Connectez-vous ou Inscrivez-vous pour répondre.
Réponses
Hello,
PluXml 5.8.22 will soon be outdated
Please check PluXml 5.10.0-rc2 and latest:
https://github.com/pluxml/PluXml/releases
Thanks for your report
Accès à mon dépôt de plugins et thèmes
installe PluXml plus vite que ton ombre avec kzInstall2
Hello again,
I checked 5.10.0-rc2 version. I found Stored XSS again. This vulnerability triggrable with writer permission. Can u reach my mail address ? enesfindikpt@gmail.com
Thx.