Sharing this for those who know more about it, so it can be looked into, if you don't already know about it. I've just seen it via Mastodon.
Sorry if this is the wrong category, so please move the post if necessary.
Sharing this for those who know more about it, so it can be looked into, if you don't already know about it. I've just seen it via Mastodon.
Sorry if this is the wrong category, so please move the post if necessary.
We've addressed quite a few file upload attacks this year, but without details about the version of Grav it's hard to know exactly what this is, if it's 100% valid etc. Best advise is to always stay up to date with Grav updates, as we handle submitted security advisories in a timely fashion and release often to ensure we're putting the most secure versions of Grav out there for people to update to.
Hi Andy, thanks for response. However, this is not about me. I shared this because every major cyber news type website is featuring this news - so it's maybe a big problem for the reputation of Grav as a secure CMS. Perhaps your great team might consider a public statement, and release your response to this particular attack, to assure the wider dev community, if you haven't done that already.
Check out just how widely this is being shared, for example: https://search.brave.com/search?q=shinyhunters+Grav+CMS
Log in to reply.
| Topic | Participants | Replies | Views | Activity |
|---|---|---|---|---|
| 1 | 133 | 1 week ago | ||
| 3 | 335 | 1 month ago | ||
| 3 | 445 | 2 months ago | ||
| 3 | 320 | 2 months ago | ||
| 3 | 433 | 2 months ago |