Adam Howard
Well-known member
I do not mean to post this twice, but I am well aware not everyone follows the add-on threads, religiously. Just as I am also aware not everyone visits TapaTalk's own support forums.
And since they have personally decided to remain silent on this issue, I thought it best to make a small announcement (draw to attention) that there is/was a security concern in TapaTalk; it was patched, but TapaTalk has decided to NOT inform people to patch or update to resolve this flaw (no notice or update issued publicly).
This security issue is directly with TapaTalk and not the XenForo development, but if you do have TapaTalk running, you should update accordingly (re-apply the same version, but using the newer files).
And since they have personally decided to remain silent on this issue, I thought it best to make a small announcement (draw to attention) that there is/was a security concern in TapaTalk; it was patched, but TapaTalk has decided to NOT inform people to patch or update to resolve this flaw (no notice or update issued publicly).
Source: https://support.tapatalk.com/threads/tapatalk-cross-site-scripting-vulnerability.24719/TapaTalk said:Hi,
This issue has been addressed in April 26th, 9 days before this site published the issue. However, since this is a low risk item - we have simply replaced all the plugins that are affected. If this is concerning you and If you have updated the plugin after April 26th, you are not affected.
This security issue is directly with TapaTalk and not the XenForo development, but if you do have TapaTalk running, you should update accordingly (re-apply the same version, but using the newer files).
Attachments
Last edited: