The issue is a cross site scripting (XSS) flaw that could allow an attacker to steal cookies or force a user to take actions without their consent or knowledge (possibly including administrative actions).
We would like to thank @batpool52! for bringing this to our attention.
If you have any questions relating to installing this patch or upgrading to the new version, please post in the Media Gallery Support forum.
Method 1: Upgrade to the New Version
The security fix can be applied by downloading XenForo Media Gallery 1.0.9 from your customer area and upgrading XenForo Media Gallery as normal.
This release also fixes an issue with view permissions not being set on new installs for the Example Category.
Method 2: Install the Patch
Download the patch zip file attached to the end of this message. It contains 8 files:
Note that this patch supersedes version 1.0.8, therefore you only need to apply this patch to resolve the issues.
Note that with this method there is no outward indication that the patch has been applied. We recommend upgrading if possible.
43.9 KB Views: 175
Last edited by a moderator: