ตัวแก้ไขธีม



XenForo 1.3.10 Released (Security Fix)

ข่าว XenForo 1.3.10 Released (Security Fix)

During routine internal testing, we discovered a security issue within XenForo 1.3 and newer. The issue allows a cross site scripting (XSS) attack to potentially be triggered via a specially crafted profile post. XSS issues may allow an attacker to steal data (including cookies) or force a user to take actions without their consent or knowledge (possibly including administrative actions).

We strongly recommend all XenForo customers follow one of the steps below to resolve this issue.

If you have any questions relating to installing this patch or upgrading to the new version, please post in the Upgrade Support forum.

Method 1: Upgrade to the New Version (Recommended)

You may upgrade to XenForo 1.3.10 (or the latest versions of 1.4 or 1.5) to fix this issue. You should upgrade as you would to any other release. If you take this approach, you should not apply the patch below.

Customers with an active license may download this version from their customer area. Full details for how to install and upgrade XenForo can be found in the XenForo Manual.

Method 2: Install the Patch

Download the patch zip file attached to the end of this message. It contains 1 file:
  • library/XenForo/Helper/String.php
This file should be uploaded to your server, overwriting the existing file of the same name.

Note that with this method there is little outward indication that the patch has been applied. The only indication is that any patched file will appear to not have the correct contents in the file health check. We recommend upgrading if possible.
 

ไฟล์แนบ

  • xf_patch_1310.zip
    xf_patch_1310.zip
    5.9 กิโลไบต์ · จำนวนการดู: 420


กระทู้ที่คล้ายกัน

  • บทความ บทความ
Today, we have released security maintenance updates for all supported XenForo releases from XenForo 2.2.0 through XenForo 2.3.12, together with applicable XenForo Media Gallery updates. These...
ตอบกลับ
0
จำนวนการดู
58
  • บทความ บทความ
XenForo 2.3.13 is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo 2.3 upgrade to this release to benefit from...
ตอบกลับ
0
จำนวนการดู
88
  • บทความ บทความ
Today, we are releasing XenForo 2.2.17 to address a potential security vulnerability. We recommend that all customers running XenForo 2.2 upgrade to 2.2.17 or use the patch instructions below as...
ตอบกลับ
0
จำนวนการดู
913
  • บทความ บทความ
If you are running XenForo 2.3.13, these additional patches do not apply to you. Today we are releasing a further round of patches for all releases from XenForo 2.2.0 - 2.3.12, alongside...
ตอบกลับ
0
จำนวนการดู
42
  • บทความ บทความ
XenForo 2.2.18 has also been released. Please refer to the release notes above. Only two of the three security issues apply to XenForo 2.2.18. The stored XSS is not applicable. We recommend doing...
ตอบกลับ
0
จำนวนการดู
274


กลับ
ยอดนิยม ด้านล่าง