Security Advisory: WHMCS Stored XSS
This is a security release for WHMCS. Update the product on every affected server to the patched release — there is no workaround, and unpatched servers remain exposed until updated.
Затронутые версии
8.7.0 and earlier
Исправленная версия
8.7.1
Команда обновления по умолчанию
yum update -y
Команды исправления
Any supported OS
cd /var/www/html
php composer.phar update whmcs/core
Что это значит по лицензии SharedLicense
Your SharedLicense license itself is not affected — this is a change in WHMCS software, not in licensing. Apply it on every affected server: update to the fixed release from the WHMCS Admin Area. Licenses keep working through updates; nothing needs re-issuing or re-activating.
A stored cross-site scripting (XSS) vulnerability was found in the WHMCS admin panel, allowing an authenticated user to inject malicious scripts.
Источники
Предупреждения о безопасности
Похожие предупреждения
Проверьте систему на уязвимости
Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.
Проверьте свою систему