[GH-ISSUE #3662] High severity vuln (contact me) #2427

Closed
opened 2026-02-26 07:35:31 +03:00 by kerem · 8 comments
Owner

Originally created by @IgorDuino on GitHub (Mar 28, 2024).
Original GitHub issue: https://github.com/NginxProxyManager/nginx-proxy-manager/issues/3662

Hello, I found a medium-high severity vulnerability in the code. Contact me by mail or LinkedIn - igordoinno. I will provide exploit to patch it

Originally created by @IgorDuino on GitHub (Mar 28, 2024). Original GitHub issue: https://github.com/NginxProxyManager/nginx-proxy-manager/issues/3662 Hello, I found a medium-high severity vulnerability in the code. Contact me by mail or LinkedIn - igordoinno. I will provide exploit to patch it
kerem 2026-02-26 07:35:31 +03:00
  • closed this issue
  • added the
    bug
    label
Author
Owner

@hairy-tortoise commented on GitHub (Apr 6, 2024):

Did he contact you?

<!-- gh-comment-id:2040815950 --> @hairy-tortoise commented on GitHub (Apr 6, 2024): Did he contact you?
Author
Owner

@IgorDuino commented on GitHub (Apr 6, 2024):

No ☹️

<!-- gh-comment-id:2041083126 --> @IgorDuino commented on GitHub (Apr 6, 2024): No ☹️
Author
Owner

@HakanP commented on GitHub (May 10, 2024):

Any update/news on this?

<!-- gh-comment-id:2104071437 --> @HakanP commented on GitHub (May 10, 2024): Any update/news on this?
Author
Owner

@IgorDuino commented on GitHub (May 15, 2024):

Any update/news on this?

No

<!-- gh-comment-id:2112363046 --> @IgorDuino commented on GitHub (May 15, 2024): > Any update/news on this? No
Author
Owner

@k1ng440 commented on GitHub (Jun 12, 2024):

It's been over a month. You should post it publicly

<!-- gh-comment-id:2163666934 --> @k1ng440 commented on GitHub (Jun 12, 2024): It's been over a month. You should post it publicly
Author
Owner

@HakanP commented on GitHub (Jun 12, 2024):

@jc21 Have you seen this?

<!-- gh-comment-id:2163852728 --> @HakanP commented on GitHub (Jun 12, 2024): @jc21 Have you seen this?
Author
Owner

@IgorDuino commented on GitHub (Jun 28, 2024):

@jc21, it is RCE vuln, lets fix it

<!-- gh-comment-id:2195866741 --> @IgorDuino commented on GitHub (Jun 28, 2024): @jc21, it is RCE vuln, lets fix it
Author
Owner

@jc21 commented on GitHub (Jun 28, 2024):

My email is all over the codebase, jc@jc21.com feel free to send through the problem.

<!-- gh-comment-id:2195868667 --> @jc21 commented on GitHub (Jun 28, 2024): My email is all over the codebase, jc@jc21.com feel free to send through the problem.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/nginx-proxy-manager-NginxProxyManager#2427
No description provided.