Organize opinions on miniBB-forums, collecting them
with the Polls & Surveys addon! Click here to read more.
Polls addon for miniBB
miniBB ®
 
miniBB Community Forum
 | Forums | File Bank | Sign Up | Reply | Search | Statistics | Manual |
News & Announcements miniBB Community Forum / News & Announcements /
Short link for this topic:

Few addons update because of CSRF/XSRF vulnerability

 
Author Paul
CEO
#1 | Posted: 7 Jun 2007 10:24
As reported previously and because miniBB version 2.0.5 has been released, the discovered CSRF vulnerability allows attacker to force administrative persons delete some data without their allowance. Recently, all miniBB addons also have been updated regarding this issue.

They include:

Avatars
Moving replies (contains update regarding avatar addon only, addon_movepost2.php + bb_plugins.code)

Premoderation
File Upload
File Storage
Polls & Surveys

Despite the discovered vulnerability has a medium level, we recommend everybody to upgrade to the new version and update all addons as well.

The mentioned addons are now compatible ONLY with the latest release 2.0.5.

Premium addons customers are welcome to get newest versions entering the customer area.
Author Karel II
Forums Member
#2 | Posted: 8 Jun 2007 00:21 | Edited by: Karel II
Thanks for the update. As for Polls & Surveys, is it already "compatible" with Human Authorize add-on (and vice versa)? (I would like to solve as many things possible with as few pre-paid downloads as possible :) ).
Author Paul
CEO
#3 | Posted: 8 Jun 2007 03:27
Yes, Polls addon (version 1.0.1) and Captcha module (version 1.2) presented in Customers area are currently compatible.

Sorry for still not announcing this... I know Polls addon has been not mentioned in News by this time, but this all because I just would like to work on some other things before. I hope to announce and clarify all that things in the nearest future.
 
News & Announcements miniBB Community Forum / News & Announcements / Few addons update because of CSRF/XSRF vulnerability Top
Your Reply Click this icon to move up to the quoted message

» Username  » Password 
You are welcome to post anonymously by entering a nickname with no password (if that nickname has not been taken by another member) or by leaving both fields empty. If you have a forums membership account, you can also sign in from this page without posting a message, or sign in and post at once.


Before posting, make sure your message is compliant with our forum posting rules. If not, it may be locked or deleted with no explanation.

 
miniBB Community Forum Powered by Free Forum Software miniBB ® Features  Requirements  Demo  Download  Showcase  Gallery of Arts
Compiler  Premium Extensions  Premium Support  License  Contacts