WHMCS 9.0.0 Security Update
Add clarifying messaging on Integration Links regarding Captcha
Standard-Update-Befehl
Update WHMCS to the latest version via the Admin Area (Utilities > Update WHMCS).
Was das unter einer SharedLicense-Lizenz bedeutet
Your SharedLicense license itself is not affected — this is a change in WHMCS software, not in licensing. Apply it on every affected server: update to the fixed release from the WHMCS Admin Area. Licenses keep working through updates; nothing needs re-issuing or re-activating.
9.0.0 (Release Candidate) Security Fixes
WHMCS 9.0.0 is a security maintenance release. It bundles a number of security hardening changes. Below is an explanation of what each fix addresses, along with the affected versions and the update path.
Add clarifying messaging on Integration Links regarding Captcha
Integration links now clearly communicate the CAPTCHA requirement, so users are not confused when a challenge is presented.
Improve Password Reset error messaging when a password does not meet minimum security requirements
The password reset form now returns a precise error when a new password fails the minimum-security policy, so users can correct it instead of getting a generic failure.
Add Captcha Protection to Password Reset form
The password reset form now requires a CAPTCHA, blocking automated attempts to enumerate or reset accounts.
Prevent erroneous CSRF block when accessing MarketConnect services
A valid CSRF token is no longer wrongly rejected on MarketConnect pages, removing a false-positive block that could break legitimate requests.
Affected Versions and Remediation
Apply the update to the latest patch release of your WHMCS branch. WHMCS supports updating in place through the Admin Area (Utilities > Update WHMCS) or by uploading the release package. Back up both your WHMCS files and database before updating.
Referenzen
System auf Schwachstellen prüfen
Wählen Sie Ihr Produkt und Betriebssystem, um die passenden Fix-Befehle zu sehen.
System prüfen