Blesta version 6 has been released! Read More.
All posts
Security 2013-10-24 · Cody · 1 min read

Security Advisory - Plugin vulnerabilities

Plugin XSS advisory: the System Overview and Feed Reader plugins in Blesta 3.0.0 through 3.0.4 render content unsanitized. Fixed in the 3.0.5 patch.

Affected Versions

Versions 3.0.0 through 3.0.4 are affected.

Description

Some content may be rendered in both the System Overview and Feed Reader plugins without proper sanitization, making them vulnerable to cross-site scripting (XSS) attacks. Patch release 3.0.5 corrects these vulnerabilities. Uninstalling the affected plugins will also mitigate any potential attacks.

Resolution

Upgrade to version 3.0.5, or uninstall the affected plugins. Related tasks:

  1. CORE-829
  2. CORE-830
Credits

These issues were discovered by the Blesta Development Team.

30-day free trial · No credit card · Your server

Read enough. Run it.

Everything on this blog ships in the box. Full product, free for 30 days, on your own server.

Download  6.0.0