Security Advisory – Various Staff Permission Issues
Security advisory: moderate staff permission flaws in Blesta 3.0.0-3.0.9 and 3.1.0-3.1.1 allow ACL bypass and delayed logout of inactive staff. Fixed in 3.0.10 and 3.1.2.
Blog · category
Every post filed under Security — newest first.
Security advisory: moderate staff permission flaws in Blesta 3.0.0-3.0.9 and 3.1.0-3.1.1 allow ACL bypass and delayed logout of inactive staff. Fixed in 3.0.10 and 3.1.2.
Security advisory: a moderate staff permission escalation flaw in Blesta 3.0.0-3.0.8 and 3.1.0 lets valid staff gain permissions via crafted URLs. Fixed in 3.0.9 and 3.1.1.
Cross-site scripting advisory for Blesta 3.0.0 through 3.0.6: client, admin, and Support plugin interfaces render content unsanitized. Fixed in 3.0.7.
Plugin XSS advisory: the System Overview and Feed Reader plugins in Blesta 3.0.0 through 3.0.4 render content unsanitized. Fixed in the 3.0.5 patch.
Cross-site scripting advisory for Blesta 3.0.0 through 3.0.3: two message types render without sanitization. Both issues are fixed in the 3.0.4 patch.
30-day free trial · No credit card · Your server
Everything on this blog ships in the box. Full product, free for 30 days, on your own server.