MyBB 1.6.9 Security Release

Discussion in 'MyBB Discussions' started by News Bot, Dec 14, 2012.

  1. News Bot

    News Bot Regular Member

    Joined:
    Apr 28, 2011
    Messages:
    429
    Likes Received:
    63
    Location:
    Cyber Space
    MyBB 1.6.9 is now available from the MyBB website and is a security release for the 1.6 series.
    What’s added/changed in this version?

    It has come to our attention that there is an SQL injection vulnerability in all versions of MyBB, including MyBB 1.6.8. We advise all MyBB forum owners to upgrade their forum as soon as possible.
    With thanks to frostschutz and StefanT for finding and reporting these issues.
    Vulnerabilities fixed:
    • High Risk: An SQL vulnerability when editing a post
    • Medium Risk: CAPTCHA systems non effective, providing possible brute-force access
    Bugs fixed:
    • An issue with the editor not working in Firefox 16 and above
    We apologise for any inconvenience.
    Upgrading from 1.6.8 and Other Versions

    Before performing any upgrade please remember to backup your forum’s files and database and store them safely. If you have edited core files, including language files, please make sure you make a changelog for these changes so you can make them again once the upgrade is complete.
    To upgrade, follow the Upgrading process. The upgrade script is required. There are changes to 1 language file (messages.lang.php). There are changes to 3 templates (portal_welcome_guesttext, loginbox & codebuttons).
    If you’re using MyBB 1.6.8
    If you’re using MyBB 1.6.7 or below
    Reporting MyBB Security Vulnerabilities

    If you think you’ve found a vulnerability in MyBB, we advise you not to publicly post it on these forums or publicly release information about it elsewhere until we’ve had time to prepare and release a patch.
    As always, you can send through security related messages on the MyBB website from the Contact Us page or in our Private Inquiries forum – where you can start a new thread that only you and the MyBB Team can see.
    Thank you,
    MyBB Team

    afeeds_wordpress_com_1_0_comments_blogdotmybbdotcom_wordpress_com_1947__.png astats.wordpress.com_b.gif_d11393d58fa4a7fae4b8dbc2954817ca.gif

    Continue reading...
     
  2. Miner

    Miner Forum Theme designer

    Joined:
    Aug 25, 2012
    Messages:
    72
    Likes Received:
    53
    Location:
    India
    Thanks for the info.
     
    Brandon likes this.

Share This Page