XenForo XenForo 2.1.14 Released (Security Fix)

C T [Bot]

New member
Note: This version supersedes the previously released XenForo 2.1.13.

Today, we are releasing XenForo 2.1.14 to address a potential security vulnerability. We recommend that all customers still running XenForo 2.1 upgrade to 2.1.14 or use the attached patch file as soon as possible.

The issue relates to HTML attribute injection which can be triggered when rendering editor content, such as when a post is edited or quoted.

XenForo extends thanks to @PaulB, the team at...

Read more

Continue reading...
 
Back
Top