Security Advisory: WHMCS Stored XSS
This is a security release for WHMCS. Update the product on every affected server to the patched release — there is no workaround, and unpatched servers remain exposed until updated.
Versiones afectadas
8.7.0 and earlier
Versión parcheada
8.7.1
CMD de actualización por defecto
yum update -y
Comandos de corrección
Any supported OS
cd /var/www/html
php composer.phar update whmcs/core
Lo que esto significa bajo una licencia de SharedLicense
Your SharedLicense license itself is not affected — this is a change in WHMCS software, not in licensing. Apply it on every affected server: update to the fixed release from the WHMCS Admin Area. Licenses keep working through updates; nothing needs re-issuing or re-activating.
A stored cross-site scripting (XSS) vulnerability was found in the WHMCS admin panel, allowing an authenticated user to inject malicious scripts.
Referencias
Comprueba tu sistema en busca de vulnerabilidades
Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.
Comprueba tu sistema