XenForo 2.1.10 Patch 2 Released Full / Upgrade (Includes Security Fix)

XF 2.1 XenForo 2.1.10 Patch 2 Released Full / Upgrade (Includes Security Fix)

  • Auteur de la discussion Auteur de la discussion laurent68
  • Date de début Date de début

Add-on xenforo 2

Ressources et modules complémentaires pour XenForo 2

Styles xenforo 2

Styles / Thèmes et apparence pour xenforo 2

Templates xenforo 2

Codes pour modifier les templates sur xenforo 2

Section Premium

Add-on et Styles pour membre Premium
XenForo 2.1.10 Patch 2 Released Full / Upgrade (Includes Security Fix)

XF 2.1 XenForo 2.1.10 Patch 2 Released Full / Upgrade (Includes Security Fix)

  • Auteur de la discussion Auteur de la discussion laurent68
  • Date de début Date de début
Catégorie Catégorie Generale
Titre du sujet Titre du sujet XenForo 2.1.10 Patch 2 Released Full \/ Upgrade (Includes Security Fix)
Auteur de la discussion Auteur de la discussion laurent68
Date de début Date de début
Réponses Réponses 22
Affichages Affichages 2 221
Réaction Réaction 11
Dernier message par Dernier message par Lokiken

laurent68

Fondateur

Staff
fondateur
Réputation: 100%
Discussions
4 644
Messages
12 049
Solutions
81
J'aime
7 606
Points
198
XenForo 2.1.10 is now available for all licensed customers to download. We recommend that all customers running previous versions of XenForo 2.1 upgrade to this release to benefit from increased stability.

Most importantly, this release fixes a security vulnerability in XenForo.

The issue is a XSS vulnerability. XSS (Cross Site Scripting) issues allow scripts and malicious HTML to be injected into the page, potentially allowing data theft or unauthenticated access. The vulnerability requires some very specific steps to be taken, involving pasting malicious content into the XenForo rich text editor, which may mean it is difficult to trigger. XenForo extends thanks to @TickTackk for reporting the issue.

While we recommend doing a full upgrade to resolve this issue, you can also patch the issue yourself with the attached file.

To patch your existing installation, please follow these steps:

  1. Download the patch files which are contained in a file called 2110patch.zip
  2. Extract the zip file to your computer, which should contain the following files:
    1. upload/js/xf/editor.js
    2. upload/js/xf/editor.min.js
    3. upload/js/xf/editor-compiled.js
  3. Upload the contents of the upload directory to the root of your XF installation.
  4. This will overwrite the following files:
    1. js/xf/editor.js
    2. js/xf/editor.min.js
    3. js/xf/editor-compiled.js
Note: If you decide to patch the files instead of doing a full upgrade, your "File health check" will report these three files as having "Unexpected contents". Because these files no longer contain the same contents your version of XF was shipped with, this is expected and can be safely ignored.

For instructions on how to resolve the issue by upgrading, and to see what else has changed in XenForo 2.1.10, please read on.

Download XenForo 2.1.10
or
Upgrade directly from within your control panel

When we released XenForo 2.0.2 we told you that we wanted to start collecting certain information about your XenForo installation and the server on which it is installed. The data that we collect is your PHP version, MySQL version and your XenForo version. This information helps us make important decisions such as which minimum PHP version we should target for future releases and helps us get a better understanding of how quickly new XF versions are adopted.

In addition to the aforementioned data, we would also like to start getting an understanding of how many add-ons our customers have installed plus the specific add-on IDs of any official XenForo add-ons you have installed.

During this upgrade you will be prompted again whether you would like to provide the usage statistics or not.

This information is, and always will be, entirely anonymous and does not include any personal or private information, but it is a huge help.

Some of the other changes in XF 2.1.10 include :

The following public templates have had changes :
  • _help_page_bb_codes
  • app_body.less
  • bb_code_tag_attach
  • code_editor
  • conversation_list
  • core_datalist.less
  • core_input.less
  • core_menu.less
  • core_overlay.less
  • editor.less
  • editor_base.less
  • editor_dialog_media
  • forum_post_quick_thread
  • forum_post_thread
  • forum_post_thread_chooser
  • forum_view
  • lightbox.less
  • lost_password_confirm
  • PAGE_CONTAINER
  • payment_cancel_recurring_confirm
  • payment_initiate.less
  • quick_reply_macros
  • share_page_macros
  • thread_reply
  • thread_view
  • widget_html
Where necessary, the merge system within the "outdated templates" page should be used to integrate these changes.

As always, new releases of XenForo are free to download for all customers with active licenses, who may now grab the new version from the customer area.

Note: add-ons, customizations and styles made for XenForo 1.x are not compatible with XenForo 2.x. If your site relies upon these for essential functionality, ensure that a XenForo 2 version exists before you start to upgrade. We strongly recommend you make a backup before attempting an upgrade.

Current Requirements

Please note that XenForo 2.1.x has higher system requirements than XenForo 1.x.

The following are minimum requirements :
  • PHP 5.6 or newer (PHP 7.4 recommended)
  • MySQL 5.5 and newer (Also compatible with MariaDB/Percona etc.)
  • All of the official add-ons require XenForo 2.1.
  • Enhanced Search requires at least Elasticsearch 2.0.
Installation and Upgrade Instructions for XenForo 2.1

Full details of how to install and upgrade XenForo can be found in the XenForo 2 Manual.

If you are already running XF 2.1 or above we strongly recommend upgrading directly from within your control panel.

Note that when upgrading from XenForo 1.x, all add-ons will be disabled and style customizations will not be maintained. New versions of add-ons will need to be installed and customizations will need to be redone. We strongly recommended that you make a backup before attempting an upgrade. Once upgraded, you will not be able to downgrade without restoring from a backup.

Télécharger Version Full :
Vous devez répondre avant de pouvoir voir le contenu des données cachées.
Télécharger Version Upgrade :
Vous devez répondre avant de pouvoir voir le contenu des données cachées.
Patch 2 Released :

Shortly after releasing 2.1.10, we became aware of an incompatibility related to how some add-ons add custom CSS to the control panel. This could lead to the control panel appearing unstyled. In order to resolve this, we have released XenForo 2.1.10 Patch 2.

You can perform the upgrade directly from your control panel by going to Tools > Check for upgrades (<url>/admin.php?tools/upgrade-check if you do not see the link due to display issues). You can also download the update from your Customer area and upgrade manually.

(Note that Patch 1 was briefly released and has been superseded with Patch 2 to resolve this issue.)

Télécharger Patch2 :
Vous devez répondre avant de pouvoir voir le contenu des données cachées.
Pour ne pas avoir cette erreur télécharger la version que j'ai modifier (Upgrade)

sejm.png


Télécharger la version upgrade modifier 2.1.10 :
Vous devez répondre avant de pouvoir voir le contenu des données cachées.
 
Merci l'ami tjr au top ;)
Publication fusionnée automatiquement :

après installation 2 erreurs

1590710036984.png
 
Dernière édition:
Merci l'ami tjr au top ;)
Publication fusionnée automatiquement :

après installation 2 erreurs

1590710036984.png
Tu as installer quel version ? (Update ou Full )

J'ai modifier le fichier hashes.json dans la version upgrade.
Essais en remplacent le hashes.json fichier par celui-la : hashes

A remplacer dans le fichier src/addons/XF/
 
Merci pour ce partage
 
Tu as installer quel version ? (Update ou Full )

J'ai modifier le fichier hashes.json dans la version upgrade.
Essais en remplacent le hashes.json fichier par celui-la : hashes

A remplacer dans le fichier src/addons/XF/
Nickel problème réglé ;) merci pour ta rapidité
 
Merci, je prend mais je fais pas la mise à jour , à chaque fois j'ai un problème...k546
 
Salut a tous, merci, en faite je voudrais comprendre le pourquoi, sur le site officiel de xenforo, j'ai une licence valide mais je n'arrive pas a trouver XenForo 2.1.10 Patch 2 Released pour que je la telecharge, je trouve que la version 2.1.8 patch 2, merci
 
Hey ben mercie à vous :3
Je prend :)
 
parfait
merci

mais j ai des erreurs

1592298505342.png

1592298563480.png


j ai reconstruit et rien de changé, je pense pas avoir fait de betises......


merci de votre aide .....

mise a jour:
j ai desinstall chat 2.1.12 et remis 2.1.8 et impek
 
Dernière édition:
Sujets similaires Les plus vues Voir plus
Retour
Haut Bas