กรุณาปิด โปรแกรมบล๊อกโฆษณา เพราะเราอยู่ได้ด้วยโฆษณาที่ท่านเห็น
Please close the adblock program. Because we can live with the ads you see


thxf.org

ข่าว XenForo 1.4.10 Released (Security Fix)

We have recently become aware of a security issue within XenForo and have released a patch and new version (XenForo 1.4.10) to resolve this issue. We strongly recommend all XenForo customers follow the steps below to resolve this issue.

The issue is a cross site scripting (XSS) flaw that could allow an attacker to steal cookies or force a user to take actions without their consent or knowledge (possibly including administrative actions).

If you have any questions relating to installing this patch or upgrading to the new version, please post in the Upgrade Support forum.

Method 1: Upgrade to the New Version

You may upgrade to XenForo 1.4.10 to fix this issue. You should upgrade as you would to any other release.

Customers with an active license may download this version from their customer area. Full details for how to install and upgrade XenForo can be found in the XenForo Manual.

In addition, two minor bug fixes are included:
  • Fixed a small styling issue with the Admin Navigation evident in Microsoft Edge browser.
  • Adjusted the regex matching for stripping BB code to include underscores in closing tags.

Method 2: Install the Patch

Download the patch zip file attached to the end of this message. It contains 4 files:
  • library/XenForo/DataWriter.php
  • library/XenForo/Install/View/ErrorServer.php
  • library/XenForo/ViewAdmin/Error/ServerError.php
  • library/XenForo/ViewPublic/Error/ServerError.php
These 4 files should be uploaded to your server, overwriting the existing files of the same names.

Note that with this method there is no outward indication that the patch has been applied. We recommend upgrading if possible.
 

ไฟล์แนบ

  • xf_patch_1410.zip
    xf_patch_1410.zip
    15.7 กิโลไบต์ · จำนวนการดู: 301

กระทู้ที่คล้ายกัน

  • บทความ บทความ
Today, we are releasing XenForo 2.2.17 to address a potential security vulnerability. We recommend that all customers running XenForo 2.2 upgrade to 2.2.17 or use the patch instructions below as...
ตอบกลับ
0
จำนวนการดู
470
thxf.org 
  • บทความ บทความ
XenForo 2.3.5 is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo 2.3 upgrade to this release to benefit from...
ตอบกลับ
0
จำนวนการดู
268
thxf.org 
  • บทความ บทความ
XenForo 2.3.6 is now available for all licensed customers to download. We strongly recommend that all customers running previous versions of XenForo 2.3 upgrade to this release to benefit from...
ตอบกลับ
0
จำนวนการดู
652
thxf.org 
  • บทความ บทความ
Security Fix Today we are advising all customers running XenForo that a potential security vulnerability has been identified. All affected customers running XenForo 2.3.0 should upgrade to XenForo...
ตอบกลับ
0
จำนวนการดู
258
  • บทความ บทความ
Security Fix Today we are advising all customers running XenForo that a potential security vulnerability has been identified. All affected customers should either upgrade to XenForo 2.1.15 or...
ตอบกลับ
1
จำนวนการดู
375

กรุณาปิด โปรแกรมบล๊อกโฆษณา เพราะเราอยู่ได้ด้วยโฆษณาที่ท่านเห็น
Please close the adblock program. Because we can live with the ads you see
กลับ
ยอดนิยม ด้านล่าง