• Downloading from our site will require you to have a paid membership. Upgrade to a Premium Membership from 10$ a month today!

    Dont forget read our Rules! Also anyone caught Sharing this content will be banned. By using this site you are agreeing to our rules so read them. Saying I did not know is simply not an excuse! You have been warned.

XenForo 2.1.12 Released (Security Fix)

Admin

Well-Known Member
Staff member
Administrator
Today, we are releasing XenForo 2.1.12 to address two potential security vulnerabilities. We strongly recommend that all customers running XenForo 2.1 upgrade to 2.1.12 or use the attached patch file as soon as possible.

The issues are XSS vulnerabilities. XSS (Cross Site Scripting) issues allow scripts and malicious HTML to be injected into the page, potentially allowing data theft or unauthenticated access.

XenForo extends thanks to security researcher Vincent ibn Winnie for reporting the issues.

We recommend doing a full upgrade to resolve the issues, but a patch can be applied manually. See below for further details.

If you are currently running 2.1, the automatic upgrade check will now allow you to upgrade to 2.1.12 within your control panel. Once you are running the latest 2.1 release, it will report that an upgrade to 2.2 is available. If you would like to upgrade to 2.1.12 and the control panel reports that 2.2.0 is available, you may manually check for upgrades via Tools > Check for upgrades.

Please be aware that XenForo 2.0 is no longer supported or receiving security updates. We strongly recommend that customers running 2.0 upgrade to the current version.

Applying a patch manually​

Download the 2112patch.zip file attached to this message. It will contain the following file:
  1. src/XF/BbCode/Renderer/Html.php
Extract the zip file to your computer and upload the contents to the root of your XenForo installation. This should overwrite the files on your server with the new version.

Note: If you decide to patch the files instead of doing a full upgrade, your "File health check" will report these three files as having "Unexpected contents". Because these files no longer contain the same contents your version of XF was shipped with, this is expected and can be safely ignored.

As always, new releases of XenForo are free to download for all customers with active licenses, who may now grab the new version from the customer area or upgrade from your Admin control panel (Tools > Check for upgrades...).
 

Facebook Comments

Similar threads
Thread starter Title Forum Replies Date
Admin XenForo 2.2.1 Released (Includes Security Fix) Xenforo 0
Admin XenForo 2.0.11 Released (Security Fix) Xenforo 0
Admin Hướng dẫn fix lỗi XSS trên Xenforo 2.0.9 - XenForo 2.0.9 Released (Security Fix) Xenforo 0
Admin XenForo 1.1.3 Released (Includes Security Fix) chưa NULL Xenforo 0
Admin XenForo 1.1.3 Released (Includes Security Fix) chưa NULL Xenforo 0
Admin XenForo & Add-ons 2.2.0 Release Candidate 2 Released (Unsupported) Xenforo 0
Admin XenForo 1.3.1 Released Xenforo 0
Admin XenForo 1.3.0 Released Xenforo 0
Admin XenForo 1.3.0 Release Candidate 2 Released (Unsupported) Xenforo 0
Admin XenForo 1.3.0 Release Candidate 1 Released (Unsupported) Xenforo 0
Admin XenForo 1.3.0 Beta 4 Released (Unsupported) Xenforo 0
Admin XenForo 1.3.0 Beta 3 Released (Unsupported) Xenforo 0
Admin XenForo 1.2.5 Released Xenforo 0
Admin XenForo 1.3.0 Beta 2 Released (Unsupported) Xenforo 1
Admin XenForo 1.3.0 Beta 1 Released (Unsupported) Xenforo 0
Admin XenForo Resource Manager 1.1.1 Released Xenforo 1
Admin XenForo 1.2.0 Release Candidate 2 Released - Nulled by VXF.VN Xenforo 0
Admin XenForo 1.2.0 Release Candidate 1 Released - Nulled by VXF.VN Xenforo 0
Admin XenForo 1.2.0 Beta 5 Released - Nulled by VXF.VN Xenforo 1
Admin XenForo 1.2.0 Beta 4 Released - Nulled by VXF.VN Xenforo 0
Admin XenForo 1.2.0 Beta 1 Released - Nulled by VXF.VN Xenforo 0
Admin XenForo 1.2.0 Beta 1 Released (Unsupported) Xenforo 0
Admin Fix [E_WARNING] inet_pton(): Unrecognized address unknown xenforo 2.2.10 Xenforo 0
V Giới hạn dung lượng ảnh tải lên trong Xenforo 2 Xenforo 0
V Hướng dẫn tạo logo giống Xenforo Xenforo 4
V Help Tiện ích thống kê bài viết cho Xenforo 2 Xenforo 0
hungdanchoi5 Forum Xenforo Thảo luận chung 1
Admin Your profile xenforo Xenforo 0
Admin Member Watch xenforo Xenforo 0
@kiss@ xin giúp đỡ về xenforo Hỗ trợ sử dụng diễn đàn 1
Admin Pro Black Xenforo 2 Xenforo 0
olalavui Hướng dẫn Enable User-ID tracking in Google Analytics for Xenforo Xenforo 3
Admin A2soft-pics - (A2)Upload Postimages picture xenforo 2 Xenforo 0
Admin Disable email and password edit xenforo 2 Xenforo 0
Admin Object Storage Adapter xenforo 2 Xenforo 0
cuongpro9x Share Tích hợp toàn bộ sticker xịn của zalo vào xenforo Xenforo 0
Admin Xenforo 2 - Random Ads Code Xenforo 0
Admin Quick Theme Switcher xenforo 2 Xenforo 0
Admin [AP] Member Bars xenforo 2 Xenforo 0
Admin Scroll Progress Xenforo 2 Xenforo 0
Admin Mocha Style xenforo 2 Xenforo 0
Admin German language - translation for XenForo 2.2.1 Xenforo 0
Admin [MMO] Navigation tab icons xenforo 2 Xenforo 0
Admin Hide Sidebar xenforo 2 Xenforo 0
Admin Media Gallery Advertisement Positions Xenforo 2 Xenforo 0
Admin Hướng dẫn xóa sổ hoàn toàn ký tự Nokia S40 cho Xenforo 2 - Remove all nokia s40 characters for xenforo 2 Xenforo 0
Admin Default Style Grey xenforo 1.x Xenforo 0
Admin Thread Prefix Colors xenforo 2 Xenforo 0
Admin Customising the layout with custom user fields xenforo 2 Xenforo 0
tiendiendev Hỏi Dùng xenforo bản bao nhiều là ổn định? Xenforo 2

Similar threads

New posts New threads New resources

Back
Top