Jun 18
All of our vBulletin 3.7.1 skins are compatible with vBulletin 3.7.1 PL2
NO template changes have been made in this maintenance release.
Read the full story here: http://www.vbulletin.com/forum/showp...84&postcount=1
NO template changes have been made in this maintenance release.
Quote:
|
Originally Posted by vBulletin.com
An XSS flaw affecting the vBulletin URL redirection system has been identified. It could allow an attacker to trick a moderator or admin into unwittingly performing an action in either the front-end or control panel that they had not intended. To resolve this issue, it is necessary to release PL2 versions of vBulletin 3.7.1 and 3.6.10.
This XSS flaw, and that which made the release of the PL1 versions necessary, was discovered by Jessica Hope and others. The upgrade process is the same as the PL1 releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required. As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited. |
News Source: vBulletin Skins - Announcements
Full Story: Read here
Recent Comments