Help - Search - Members - Calendar
Full Version: Vbulletin 3.7.1 Pl2 / Vbulletin 3.6.10 Pl2 Released
TotalChoice Hosting Family Forums > TotalChoice Hosting General Support > Security Discussions > Software/Scripts/Other Alerts
TCH-Thomas
vBulletin 3.7.1 PL2 / vBulletin 3.6.10 PL2 has been released.

From their announcement:
An XSS flaw affecting the vBulletin URL redirection system has been identified. It could allow an attacker to trick a moderator or admin into unwittingly performing an action in either the front-end or control panel that they had not intended. To resolve this issue, it is necessary to release PL2 versions of vBulletin 3.7.1 and 3.6.10.

The upgrade process is the same as the PL1 releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.

Read more / Get it at: vbulletin.com/forum/showthread.php?t=275889
TCH-Bruce
Thanks Thomas
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.