Potential information leakage in newsbox() function

A place for security related announcements and discussions - please check this forum frequently!
Post Reply
cmb
Posts: 14225
Joined: Tue Jun 21, 2011 11:04 am
Location: Bingen, RLP, DE
Contact:

Potential information leakage in newsbox() function

Post by cmb » Tue Oct 17, 2017 3:15 pm

Hi!

A potential information leakage in the newsbox() function has been found, and already fixed in CMSimple_XH 1.7.1. Although CMSimple_XH 1.6 had it's end of life, and it not recommended to run this version anymore, if you can't yet update to 1.7.1 for whatever reason, it is recommended to fix the bug yourself. The fix is identical to the one for CMSimple_XH 1.7.0.
Christoph M. Becker – Plugins for CMSimple_XH

Post Reply