OTuGaMoDz

Xenforo 2.x.x XenForo 2.1.9 Full / Upgrade (Security Fix)

Add-on xenforo 2

Ressources et modules complémentaires pour XenForo 2

Styles xenforo 2

Styles / Thèmes et apparence pour xenforo 2

Templates xenforo 2

Codes pour modifier les templates sur xenforo 2

Section Premium

Add-on et Styles pour membre Premium
OTuGaMoDz

Xenforo 2.x.x XenForo 2.1.9 Full / Upgrade (Security Fix)

Catégorie Catégorie Generale
Titre du sujet Titre du sujet XenForo 2.1.9 Full \/ Upgrade (Security Fix)
Auteur de la discussion Auteur de la discussion OTuGaMoDz
Date de début Date de début
Réponses Réponses 15
Affichages Affichages 1 439
Réaction Réaction 5
Dernier message par Dernier message par fionei

OTuGaMoDz

:)

Premium
Donateur
Réputation: 100%
Discussions
90
Messages
732
Solutions
18
J'aime
936
Points
168
Salut la communauté

Today, we are releasing XenForo 2.1.9 and XenForo 2.0.13 to address a potential security vulnerability that may affect any customer who makes use of our PayPal payment handler.

As well as user upgrades, this may affect add-ons you have installed which process payments using our PayPal payment handler.

We recommend that all affected customers running XenForo 2.1 or XenForo 2.0 upgrade to 2.1.9 or 2.0.13 or use one of the attached patch files as soon as possible.

Specifically, the issue relates to a specially crafted callback (or IPN) which is then processed successfully using PayPal's sandbox validation endpoint instead of their live system. If successful, a purchase could be completed without your PayPal account actually receiving any funds.

There are no other fixes included in this version. There will be a further 2.1 maintenance release in the coming weeks.

Applying a Fix: Upgrading

You may upgrade to 2.1.9 or 2.0.13 to fix this issue. You should upgrade as you would to any other release.

Customers with an active license may download 2.1.9 or 2.0.13 from their customer area. Full details for how to install and upgrade XenForo can be found in the XenForo Manual.

If you are running XF 2.1 you can upgrade directly from within your control panel.

Applying a Fix: Patching
Alternatively, this issue can be fixed by applying the patch in the attached file. You should simply overwrite the following file with the version attached to this message:​
  • src/XF/Payment/PayPal.php​
The file can be found at the same path within the attachment.

Please ensure you download the correct patch for your XenForo version. If you are running XenForo 2.1 then please only download xf-patch-219.zip. If you are running XenForo 2.0 then please only download xf-patch-2013.zip.

Lien de téléchargement version full :
Vous devez répondre avant de pouvoir voir le contenu des données cachées.
Lien de téléchargement version upgrade:
Vous devez répondre avant de pouvoir voir le contenu des données cachées.

Lien de téléchargement xf-patch-219 et xf-patch-2013:

Pour voir ce contenu caché, vous devez aimer ce contenu.
 

Pièces jointes

Merci pour cette énième MAJ ...
 
Merci ! patch ajouter en pièce jointe :)
 
Sujets similaires Les plus vues Voir plus
Retour
Haut Bas