XF2 XenForo 2.1.9 and 2.0.13 Released (Security Fix)

  • Người tạo chủ đề
  • Admin
  • #1

Binzz

Staff
Thành Viên BQT
448
1,229
Thời Gian Online
30d 12h 8m
Level
0
Awards
5
Credits
1
Today, we are releasing XenForo 2.1.9 and XenForo 2.0.13 to address a potential security vulnerability that may affect any customer who makes use of our PayPal payment handler.

As well as user upgrades, this may affect add-ons you have installed which process payments using our PayPal payment handler.

We recommend that all affected customers running XenForo 2.1 or XenForo 2.0 upgrade to 2.1.9 or 2.0.13 or use one of the attached patch files as soon as possible.

Specifically, the issue relates to a specially crafted callback (or IPN) which is then processed successfully using PayPal's sandbox validation endpoint instead of their live system. If successful, a purchase could be completed without your PayPal account actually receiving any funds.

There are no other fixes included in this version. There will be a further 2.1 maintenance release in the coming weeks.

Applying a Fix: Upgrading

You may upgrade to 2.1.9 or 2.0.13 to fix this issue. You should upgrade as you would to any other release.


Applying a Fix: Patching
Alternatively, this issue can be fixed by applying the patch in the attached file. You should simply overwrite the following file with the version attached to this message:
  • src/XF/Payment/PayPal.php
The file can be found at the same path within the attachment.

Please ensure you download the correct patch for your XenForo version. If you are running XenForo 2.1 then please only download xf-patch-219.zip. If you are running XenForo 2.0 then please only download xf-patch-2013.zip.


Link tải full : https://url3s.site/D5s76OTT
 
Top

Đã phát hiện AdBlock

Ái chà chà! không nên chặn quảng cáo trên web của chúng tôi!

phần mềm chặn quảng cáo thực hiện công việc tuyệt vời trong việc chặn quảng cáo, nhưng nó cũng chặn các tính năng hữu ích của trang web của chúng tôi. mình khuyên bạn nên tắt AdBlocker đi.

Ok! Tôi đã tắt nó