Re: Any Update on Reported Vulnerability

From: "M(dot)Arslan Kabeer" <arslan(dot)whitehat(at)inbox(dot)eu>
To: "Ray O'Donnell" <ray(at)rodonnell(dot)ie>
Cc: pgsql-www(at)postgresql(dot)org
Subject: Re: Any Update on Reported Vulnerability
Date: 2021-05-03 21:50:24
Message-ID: 1620078624.6090702046a8d@mail.inbox.eu
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-www

<html>Hi there,<br />
Team kindly see that this is a P4 priority 4 vulnerability from this attack an attacker can spam your users by send them email using your website official email address, I have been rewarded 300$-350$ on this same vulnerability, kindly some sort of reward would be much appreciated.&nbsp;I have found and reported another vulnerability a critical one, kindly take a look.<br />
Always Best Regards<br />
White HaT
<div class="noTransl">----- Reply to message -----<br />
<b>Subject: </b>Re: Any Update on Reported Vulnerability<br />
<b>Date: </b>Mon, 3 May 2021, 22:56<br />
<b>From: </b> Ray O&#39;Donnell <a href="mailto:ray(at)rodonnell(dot)ie">&lt;ray(at)rodonnell(dot)ie&gt;</a><br />
<b>To: </b> <a href="mailto:arslan(dot)whitehat(at)inbox(dot)eu">&lt;arslan(dot)whitehat(at)inbox(dot)eu&gt;</a></div>

<blockquote>On 30/04/2021 18:36, arslan(dot)whitehat(at)inbox(dot)eu wrote:<br />
&gt; Hi there, Team any update on the vulnerability report,I have reported<br />
&gt; a DMARC vulnerability on 2021-04-15, and its been a while kindly<br />
&gt; update me about the vulnerability progress. I am also attaching the<br />
&gt; POC images again. I am hoping to receive a reward for the responsible<br />
&gt; disclosure of the vulnerability Kind regards White HaT<br />
<br />
There was a response at the time from a member of the relevant team,<br />
explaining that it wasn&#39;t actually a vulnerability - you&#39;ll find it in<br />
the archives.<br />
<br />
Ray.<br />
<br />
--<br />
Raymond O&#39;Donnell // Galway // Ireland<br />
ray(at)rodonnell(dot)ie</blockquote>
</html>

Attachment Content-Type Size
unknown_filename text/html 1.5 KB

In response to

Responses

Browse pgsql-www by date

  From Date Subject
Next Message Magnus Hagander 2021-05-04 10:41:03 Re: Add versions.json endpoint with latest release information
Previous Message Ray O'Donnell 2021-05-03 19:56:28 Re: Any Update on Reported Vulnerability