• Resolved Ubuntu Productions

    (@ubuntuproductions)


    Hello πŸ‘‹

    I just got an alert about this plugin been vulnerable to Cross Site Scripting:*

    Plugin Name: System Dashboard

    Vulnerability Details: Reflected Cross-Site Scripting via Filename Parameter vulnerability discovered by vgo0 in WordPress Plugin System Dashboard (versions <= 2.8.15)

    Are you going to release a fix anytime soon?

    Thanks! πŸ™

Viewing 8 replies - 1 through 8 (of 8 total)
  • Plugin Author Bowo

    (@qriouslad)

    @ubuntuproductions thanks for reporting this. Yes, this will be fixed soon. Currently fully occupied with another project. Your patience is appreciated.

    Thread Starter Ubuntu Productions

    (@ubuntuproductions)

    Thank you for your message? πŸ™

    When you say “fixed soon” do you mean in few hours, days, weeks? I might be wrong, but this vulnerability seems pretty serious πŸ˜…

    Plugin Author Bowo

    (@qriouslad)

    @ubuntuproductions Currently publishing v2.8.16 with the fix, for review by the plugins team at ww.wp.xz.cn.

    Thread Starter Ubuntu Productions

    (@ubuntuproductions)

    Awesome @qriouslad 😊 thank you very much. I truly understand that it must not be easy to allocate resources to this when you are fully occupied with another project, so really appreciate it πŸ’š

    Plugin Author Bowo

    (@qriouslad)

    @ubuntuproductions you’re welcome. Thank you for your understanding.

    System Dashboard is a free plugin I developed in my spare time. It took quite a number of hours to get to where it is now, but I’m no longer able to spend as much focus on it as I used too. I still use it to this day for my own dev workflow.

    As for the security issue’s fix, let’s wait a bit. It might take the plugin team several days to get to reviewing it. Hopefully the submitted fix is sufficient. If so, you should see an update notice (of a new version) in your wp-admin.

    Plugin Author Bowo

    (@qriouslad)

    @ubuntuproductions the security fix was approved and released as part of v2.8.18. Please update and test. Thanks again for reporting it here.

    Plugin Author Bowo

    (@qriouslad)

    p.s. if you find System Dashboard useful for your dev workflow, please kindly consider leaving a quick review for it at https://ww.wp.xz.cn/plugins/system-dashboard/#reviews. Thanks!

    Thread Starter Ubuntu Productions

    (@ubuntuproductions)

    Awesome @qriouslad , thank you for your work! πŸ™ I will definitely leave a review. Have a nice weekend.

Viewing 8 replies - 1 through 8 (of 8 total)

The topic ‘Cross Site Scripting vulnerability’ is closed to new replies.