Volver a los avisos de seguridad

WHMCS 9.0.7 Security Update

Improved security around email previews

High
WHMCS

CMD de actualización por defecto

Update WHMCS to the latest version via the Admin Area (Utilities > Update WHMCS).

Lo que esto significa bajo una licencia de SharedLicense

Your SharedLicense license itself is not affected — this is a change in WHMCS software, not in licensing. Apply it on every affected server: update to the fixed release from the WHMCS Admin Area. Licenses keep working through updates; nothing needs re-issuing or re-activating.

9.0.7 (Maintenance Release) Security Fixes

WHMCS 9.0.7 is a security maintenance release. It bundles a number of security hardening changes. Below is an explanation of what each fix addresses, along with the affected versions and the update path.

Improved security around email previews

Email previews could be used to inspect content they should not; the fix tightens access controls on the preview path so only authorized administrators can render them.

Undisclosed Security Fix

WHMCS ships several security fixes each release without publishing technical detail. These are applied as hardening of the platform and are not accompanied by a public CVE, so the specific mechanism is withheld to protect installations that have not yet updated. Upgrading is the recommended course of action.

Undisclosed Security Fix

WHMCS ships several security fixes each release without publishing technical detail. These are applied as hardening of the platform and are not accompanied by a public CVE, so the specific mechanism is withheld to protect installations that have not yet updated. Upgrading is the recommended course of action.

Undisclosed Security Fix

WHMCS ships several security fixes each release without publishing technical detail. These are applied as hardening of the platform and are not accompanied by a public CVE, so the specific mechanism is withheld to protect installations that have not yet updated. Upgrading is the recommended course of action.

Undisclosed Security Fix

WHMCS ships several security fixes each release without publishing technical detail. These are applied as hardening of the platform and are not accompanied by a public CVE, so the specific mechanism is withheld to protect installations that have not yet updated. Upgrading is the recommended course of action.

Improved security for paying invoices with PayPal Payments

The PayPal Payments gateway callback now validates the source and payload more strictly, preventing forged or replayed payment notifications.

Undisclosed Security Fix

WHMCS ships several security fixes each release without publishing technical detail. These are applied as hardening of the platform and are not accompanied by a public CVE, so the specific mechanism is withheld to protect installations that have not yet updated. Upgrading is the recommended course of action.

Affected Versions and Remediation

Apply the update to the latest patch release of your WHMCS branch. WHMCS supports updating in place through the Admin Area (Utilities > Update WHMCS) or by uploading the release package. Back up both your WHMCS files and database before updating.

Comprueba tu sistema en busca de vulnerabilidades

Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.

Comprueba tu sistema