We have recently become aware of a security issue within XenForo Media Gallery and have released a patch and new version (XenForo Media Gallery 1.0.9) to resolve this issue. We strongly recommend all XenForo Media Gallery customers follow the steps below to resolve this issue.
The issue is a cross site scripting (XSS) flaw that could allow an attacker to steal cookies or force a user to take actions without their consent or knowledge (possibly including administrative actions).
We would like to thank @batpool52! for bringing this to our attention.
If you have any questions relating to installing this patch or upgrading to the new version, please post in the Media Gallery Support forum.
Method 1: Upgrade to the New Version
The...