Volver a los avisos de seguridad

Security Advisory: WHMCS Stored XSS

This is a security release for WHMCS. Update the product on every affected server to the patched release — there is no workaround, and unpatched servers remain exposed until updated.

Medium
WHMCS

Versiones afectadas

8.7.0 and earlier

Versión parcheada

8.7.1

CMD de actualización por defecto

yum update -y

Comandos de corrección

Any supported OS

cd /var/www/html
php composer.phar update whmcs/core

Lo que esto significa bajo una licencia de SharedLicense

Your SharedLicense license itself is not affected — this is a change in WHMCS software, not in licensing. Apply it on every affected server: update to the fixed release from the WHMCS Admin Area. Licenses keep working through updates; nothing needs re-issuing or re-activating.

A stored cross-site scripting (XSS) vulnerability was found in the WHMCS admin panel, allowing an authenticated user to inject malicious scripts.

Comprueba tu sistema en busca de vulnerabilidades

Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.

Comprueba tu sistema