I'll be updating soon to 2.1.10 but for the time being, since I'll be needing to update addons and themes at the same time, I'll stick to the security fixes for a few more days.I'm going to upgrade in the evening. I think there's nothing that doesn't change. xenforo is getting better day by day
I'll be updating soon to 2.1.10 but for the time being, since I'll be needing to update addons and themes at the same time, I'll stick to the security fixes for a few more days. @ozzy47 @AddonFlare ozzy47
There is no open door in xenforo.There have already been a couple of patches that address some sort of cross site scripting vulnerability that were identified by a member exercising good faith, but wut if it were discovered by a malicious actor? Wut would deter such individual(s) from taking advantage of it and install some form of malware because of a vulnerability XF was not aware of? Is there some form of security in place to prevent these types of scripts from modifying the software before it is too late?
That we know of. Obviously there was one that got identified in time. However, I wouldn't like to only count on the goodwill of members when it comes to software vulnerabilities.There is no open door in xenforo.
If it were open, the baby forum was already history. They try to do ddos attack every day because they can't do anythingThat we know of. Obviously there was one that got identified in time. However, I wouldn't like to only count on the goodwill of members when it comes to software vulnerabilities.
Well, not necessarily. Not all malware is created to wreak havoc. You could potentially have some form of spyware silently lurking about :-0If it were open, the baby forum was already history. They try to do ddos attack every day because they can't do anything
Make me think Has the Snogsite spaminator plug-in been updated as well?
There is no need for an update, the addon is working as expected.
Well that's the very nature of any software, unfortunately. If a security issue is discovered by a bad actor then all bets are off.There have already been a couple of patches that address some sort of cross site scripting vulnerability that were identified by a member exercising good faith, but wut if it were discovered by a malicious actor? Wut would deter such individual(s) from taking advantage of it and install some form of malware because of a vulnerability XF was not aware of? Is there some form of security in place to prevent these types of scripts from modifying the software before it is too late?
Thanks Chris.... no update through as yet, running an update via the Cron Entries as advised by TH.Check for upgrades again at Tools > Check for upgrades. A further patch was released to address that issue.
We use essential cookies to make this site work, and optional cookies to enhance your experience.