BlogEngine/BlogEngine.NET

XSS on Posts and Pages

ahsan-aziz opened this issue · 1 comments

Hi team, I have identified a couple of XSS issues, can you please reach out to me at timeintospace@gmail.com? Thanks!

Hi, given the 90 days response deadline is passed, we plan to publish CVEs for these issues. Please let me know (at timeintospace@gmail.com) if you want the POC and wish to fix the issues, and we can delay the disclosure. If we don't hear anything back, we will proceed as per our responsible disclosure guidelines and obligations. I have also left a message on the contact-us page on blogengine.io. Thanks!