Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerabilities has discovered - SQL Injection #57

Closed
rajankarmakar opened this issue Apr 6, 2023 · 5 comments · Fixed by #60
Closed

Vulnerabilities has discovered - SQL Injection #57

rajankarmakar opened this issue Apr 6, 2023 · 5 comments · Fixed by #60
Assignees

Comments

@rajankarmakar
Copy link

Vulnerabilities have discovered that the currently installed version of the Intuitive Custom Post Order plugin has known security vulnerabilities. See more.

@timohubois
Copy link
Collaborator

@rajankarmakar thanks for the feedback. Personaly, I think there is some exaggeration here. Of course it is possible to change things, but for this an administrative access is needed and if this is in the possession of someone else, the plugin itself is not the problem!

@hijiriworld have you found the time to take a deeper look into the PR54. Would love to fix the security issues and use this PR as starting point.

@timohubois timohubois self-assigned this Apr 6, 2023
@sajuahmed23
Copy link

@timohubois Can you say anything about the timing of the fix or if it will be fixed by the next release?

@timohubois
Copy link
Collaborator

Would really love to fix it and currently I’m waiting for feedback from @hijiriworld, to get a better starting point.

@timohubois
Copy link
Collaborator

#54 is merged. Will start to work on this asap.

@timohubois timohubois linked a pull request Nov 19, 2023 that will close this issue
@timohubois
Copy link
Collaborator

Created a branch with some changes: https://github.com/hijiriworld/intuitive-custom-post-order/pull/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants