XenForo 2.1.13 Released (Security Fix)

STR Haberci

StarTR Haber Ekibi!
Yönetici
Haber Ekibi
Katılım
5 Eylül 2015
Mesajlar
64
Konum
Türkiye
Web sitesi
www.startr.org
İlgi Alanı
Haber
Today, we are releasing XenForo 2.1.13 to address a potential security vulnerability. We recommend that all customers still running XenForo 2.1 upgrade to 2.1.13 or use the attached patch file as soon as possible.

The issue relates to HTML attribute injection which can be triggered when rendering editor content, such as when a post is edited or quoted.

XenForo extends thanks to security researcher @PaulB, the team at @NamePros and @Xon for reporting the issues.

We...



 
Üst