Skip to content

Security report: potential findings in microblog #423

Description

@leeyu44

Hello maintainers,

I am opening this issue to establish vendor contact for a security review of microblog. The local report identifies the following potential security findings:

  • Hardcoded Secret Key Fallback - CRITICAL
  • Missing Rate Limiting - HIGH
  • Translation Proxy URL Injection - HIGH
  • IDOR on API User Endpoints - MEDIUM
  • Email Change Without Verification - MEDIUM
  • No Token Invalidation on Password Reset - MEDIUM
  • Debug Mode Enabled by Default - MEDIUM
  • CSRF Disabled on Search Form - MEDIUM

Affected version / commit tested: reported tested version; confirm with vendor

I am intentionally keeping exploit steps, payloads, and sensitive values out of this public issue. If you prefer a private channel or a GitHub Security Advisory, please point me to it and I can provide full reproduction notes there.

Reporter credit: logicfuzz

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions