FTL
Well-known member
In the post below it says:
However, when I look in the ACP, it still shows 2.2.16 and it also shows 2.2.16 in the Account section, so I'm wondering if there's an issue here. I'd therefore be grateful if you could please clarify.
@Chris D
Cloud customers have received this patch automatically and does not require an upgrade.
However, when I look in the ACP, it still shows 2.2.16 and it also shows 2.2.16 in the Account section, so I'm wondering if there's an issue here. I'd therefore be grateful if you could please clarify.
Today, we are releasing XenForo 2.2.17 to address a potential security vulnerability. We recommend that all customers running XenForo 2.2 upgrade to 2.2.17 or use the patch instructions below as soon as possible.
Notes:
a. XenForo 2.3.1 and above is not affected by this issue. If you are still running XenForo 2.3.0 you should upgrade to the latest release or apply the patch below.
b. The few XenForo Cloud customers still running XenForo 2.2 have been patched automatically.
The issue relates to a potential redirection exploit using a specially crafted URL.
XenForo extends...
Notes:
a. XenForo 2.3.1 and above is not affected by this issue. If you are still running XenForo 2.3.0 you should upgrade to the latest release or apply the patch below.
b. The few XenForo Cloud customers still running XenForo 2.2 have been patched automatically.
The issue relates to a potential redirection exploit using a specially crafted URL.
XenForo extends...
- XenForo
- Replies: 0
- Forum: Announcements
@Chris D