Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungMCP Tool Poisoning: A Name Allowlist Is Not Enough(22.09.2026 um 18:56 Uhr)
Sichere ProgrammierungGiggleGigs: A Job Board That Actually Uses AI Where It Helps(22.09.2026 um 18:57 Uhr)
Sichere ProgrammierungThe Bootstrapped SaaS Flywheel: How to Hit $10k MRR Without VC Capital(22.09.2026 um 19:05 Uhr)
Sichere ProgrammierungThe container was running software nobody built(22.09.2026 um 19:08 Uhr)
Sichere ProgrammierungYour Terminal Tasks, Everywhere: Introducing Tasku Cloud(22.09.2026 um 19:08 Uhr)
Sichere ProgrammierungMCP Tool Poisoning: A Name Allowlist Is Not Enough(22.09.2026 um 18:56 Uhr)
Sichere ProgrammierungGiggleGigs: A Job Board That Actually Uses AI Where It Helps(22.09.2026 um 18:57 Uhr)
Sichere ProgrammierungThe Bootstrapped SaaS Flywheel: How to Hit $10k MRR Without VC Capital(22.09.2026 um 19:05 Uhr)
Sichere ProgrammierungThe container was running software nobody built(22.09.2026 um 19:08 Uhr)
Sichere ProgrammierungYour Terminal Tasks, Everywhere: Introducing Tasku Cloud(22.09.2026 um 19:08 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Responsible disclosure of vulnerabilities where author probably doesn't have the ability to address the issues

I was recently evaluating a software to use for our organization. I had a look at the code (PHP) and it it is littered with vulnerabilities. I was able to do a XSS POC within 10 mins of looking at the code. Within an hour I found a dozen…

0
↗ Quelle (reddit.com)
Reagiere als Erste:r — dein Feedback zählt!

I was recently evaluating a software to use for our organization. I had a look at the code (PHP) and it it is littered with vulnerabilities. I was able to do a XSS POC within 10 mins of looking at the code. Within an hour I found a dozen of XSS and SQL injection vulnerabilities. I informed the author a week ago. After initially refuting the issue the author stopped responding. There have been no updates to the software since.

The thing is the code looks like straight from the 90s. MySQL/PHP in HTML, $_GET straight embedded in the template, $_GET straight embedded in SQL queries, tons of duplication, ... It's a total mess. As far as I can tell it has been around in this state for a decade. The only way to fix this would be to completely rewrite the system (~45k lines of code). The system is widely used (forum has 1000s of posts/ product is one of the top search results for the use case). The system is used to manage sensitive customer information.

The question is what would be a recommended approach to disclose/approach this. Looking at the code I don't think the author has the ability to rewrite the system in a secure manner. The system has been around for a long time and by the looks of it there are no exploits in he wild (there was one CVE a few years ago with exploits but the particular issue has been fixed since). I don't have the time/expertise to support someone to rewrite their commercial product. Should I just ignore it? Or should I give the author x days to fix and then disclose? Or is there some middle ground?

submitted by /u/DerThes
[link] [comments]
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Responsible disclosure of vulnerabilities where author probably doesn't have the ability to address the issues

Thematisch verwandte Begriffe: Responsible, disclosure, vulnerabilities, where · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-75517 | Novu provides an API for sending notifications through multiple channels…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick