MyBB Releases

MyBB 1.8.8 Release

Submitted by Nasyr, , Thread ID: 25827

Thread Closed
20-12-2016, 01:13 AM
#1
MyBB 1.8.8

This release fixes7 security vulnerabilitiesand58 reported issuescausing incorrect functionality of MyBB. Please be aware that not all issues have been fixed in this version in order to provide easy to manage updates.
  • Vulnerabilities:
    • Mediumrisk: Style import CSS overwrite on Windows servers
    • Medium risk: SQL Injection in the users data handler
    • Medium risk: SSRF attack in fetch_remote_file()
    • Medium risk: Possible short name access to ACP backups on Windows servers
    • Lowrisk: Stored XSS in the ACP
    • Low risk: Loose comparison false positives
    • Low risk: Possible XSS injection in ACP users module

Download --https://mybb.com/download/
Please read the award requirements here before applying for them.
Rules and Regulations | Support Section | How to use Hide Tags
Don't message me to join a group, simply request to join one here.

Users browsing this thread: