Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SECURITY] Directory Traversal Vulnerability Found #18

Open
Sp1d3rL1 opened this issue Jun 17, 2024 · 3 comments
Open

[SECURITY] Directory Traversal Vulnerability Found #18

Sp1d3rL1 opened this issue Jun 17, 2024 · 3 comments

Comments

@Sp1d3rL1
Copy link

Sp1d3rL1 commented Jun 17, 2024

We have recently discovered an Directory Traversal Vulnerability in several files in PHPVibe that cause Code Execution, and it is definitely something that should concern you. I'll report it to the PHPVibe community as soon as possible and also hope to get in touch with you soon so we can move forward with fixing the issue.
If it is convenient, You can reach me at [email protected] to get in touch and hopefully get your attention as soon as possible so that I can report the vulnerability details to you.
Finally, if you don't mind, I would like to report it to CVE as well, so I hope you know and understand.

@Sp1d3rL1 Sp1d3rL1 changed the title [SECURITY] Arbitrary File Write Vulnerability Found [SECURITY] Directory Traversal Vulnerability Found Jun 17, 2024
@PHPVibe
Copy link
Owner

PHPVibe commented Jun 29, 2024

Hi! I've received an email but my replies bounced. I've added a check to insecure files function.

@Sp1d3rL1
Copy link
Author

Sp1d3rL1 commented Jul 1, 2024

Sorry, I may have a problem with my Google mail settings. I saw your changes, but the exploit I mentioned can still bypass this restriction, so please send me an email to this email address [email protected].
Attached is a link to the exploit proof: https://github.com/751897386/PHPVibe_vulnerability_Directory-Traversal

@PHPVibe
Copy link
Owner

PHPVibe commented Jul 18, 2024

Got it now, thanks! I've added a rudimentary, but useful, cleaning function for the tokens.

https://github.com/PHPVibe/PHPVibe/commits/master/

It should wipe everything tricky and no longer allow access to file paths.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants