Welcome to Admin Junkies, Guest — join our community!

Register or log in to explore all our content and services for free on Admin Junkies.

Multiple Vulnerabilities Found In XenForo

joelr

Addicted member
Administrator
Joined
Apr 16, 2023
Messages
912
Credits
1,897
According to a recent security update shared on XenForo forums, the service addressed numerous security vulnerabilities with the latest XenForo release.

As stated, the vulnerabilities included a cross-site request forgery (CSRF) and code injection flaw that could lead to remote code execution and cross-site scripting (XSS) attacks.

XenForo credited the security researcher Egidio Romano for reporting most of these flaws via SSD Secure Disclosure. While the firm didn’t share details about the vulnerabilities in its post, SSD Secure Disclosure shared a detailed analysis in a separate advisory. These vulnerabilities include CVE-2024-38457 – a CSRF vulnerability, and CVE-2024-38458 – a remote code execution flaw.

https://xenforo.com/community/threa...-2-6-released-includes-security-fixes.222133/
 
Advertisement Placeholder
They released a patch for 2.1.15 and also for 2.1.16. You could either apply the patch manually or use the upgrade feature in the ACP if your license was active for updates/support. That was why they also released a patch that could be uploaded to the site, for those that did not have active support for the "latest & greatest" downloads.

https://xenforo.com/community/threa...-2-6-released-includes-security-fixes.222133/
 

Log in or register to unlock full forum benefits!

Log in or register to unlock full forum benefits!

Register

Register on Admin Junkies completely free.

Register now
Log in

If you have an account, please log in

Log in

Would You Rather #9

  • Start a forum in a popular but highly competitive niche

    Votes: 9 27.3%
  • Initiate a forum within a limited-known niche with zero competition

    Votes: 24 72.7%
Win this space by entering the Website of The Month Contest

Theme editor

Theme customizations

Graphic Backgrounds

Granite Backgrounds