Back to Security Advisories

Security Advisory: WHMCS Admin Password Reset Weak Token

Password reset tokens in WHMCS were generated with insufficient entropy, allowing brute-force recovery of the reset URL for administrator accounts.

High
WHMCS

Affected Versions

WHMCS 8.9.0 and earlier

Patched Version

WHMCS 8.10.1

Default Update CMD

yum update -y

Fix Commands

All Systems

Back up /var/www/html/whmcs
Download the patched release
Run the upgrade wizard at /install/upgrade

Check your system for vulnerabilities

अपना उत्पाद और ऑपरेटिंग सिस्टम चुनें ताकि आपके लिए लागू सटीक फिक्स कमांड देख सकें।

Check Your System