ExtraLicense - Buy, Sell, & Trade Your Licenses

This is a sample guest message. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your own topics and posts, as well as connect with other members through your own private inbox!

XenForo 1.2.8 Released (Security Fix)

EL PaperBoy

Well-known member
Today, we are releasing XenForo 1.2.8 to address two potential security vulnerabilities. We recommend that all customers running XenForo 1.2 or earlier upgrade to 1.2.8 or use the attached patch file as soon as possible.

The two issues are XSS vulnerabilities. XSS (Cross Site Scripting) issues allow scripts and malicious HTML to be injected into the page, potentially allowing data theft or unauthenticated access.

  • In the notices system, the name token was not escaped as expected....


XenForo 1.2.8 Released (Security Fix)

Continue reading...

 
Top