Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10.
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
Link | Tags |
---|---|
https://huntr.dev/bounties/22fdcc39-8c1a-4e4c-8eae-be3fd764f8b4 | patch third party advisory exploit |
https://github.com/publify/publify/commit/af69097d349f4c00f244c51cd3c3e937fd3387cd | third party advisory patch |