09-12-2015 , 08:49 AM
Deear member,
A maintenance had to be done and successfully completed which upgrade the forum from version 1.85 to the recent version 1.86 that help fixed several vulnerability.
Vulnerabilities:
Please let us know if you encounter any problem or error we will try our best to look into the matter.
Thanks.
A maintenance had to be done and successfully completed which upgrade the forum from version 1.85 to the recent version 1.86 that help fixed several vulnerability.
Vulnerabilities:
- Medium Risk: Forum password bypass in xmlhttp.php
- Low Risk: SQL Injection in Grouppromotions module (ACP)
- Low Risk: Possible XSS Injection in the error handler
- Low Risk: Possible XSS issues in old upgrade files
- Low Risk: Possible Full Path Disclosure in publicly accessible error log files
Please let us know if you encounter any problem or error we will try our best to look into the matter.
Thanks.