MyBB 1.6.9 Security Release

Status
Not open for further replies.

McLovin

Level 80
Thread author
Verified
Honorary Member
Malware Hunter
Forum Veteran
Apr 17, 2011
9,248
6,916
7,889
Victoria, Australia
pr.tn
MyBB said:
MyBB 1.6.9 is now available from the MyBB website and is a security release for the 1.6 series.

What’s added/changed in this version?

It has come to our attention that there is an SQL injection vulnerability in all versions of MyBB, including MyBB 1.6.8. We advise all MyBB forum owners to upgrade their forum as soon as possible.

With thanks to frostschutz and StefanT for finding and reporting these issues.

Vulnerabilities fixed:
  • High Risk: An SQL vulnerability when editing a post
  • Medium Risk: CAPTCHA systems non effective, providing possible brute-force access

Bugs fixed:
  • An issue with the editor not working in Firefox 16 and above

We apologise for any inconvenience.

Source. - Download.
 
Status
Not open for further replies.