Security issue detailsThere is a minor security problem (XSS flaw) found in aMember Pro. It affects all aMember Pro versions before 3.0.4. This problem is not urgent and cannot directly lead to hack of your website without your invention. However, it is anyway necessary to take actions against it. Fortunately, it is very easy and quick to do. For customers running old versions of aMember upgrade is NOT NECESSARY, not required, and will not make your website more secure. Just use on of patching methods below - it is quite enough. PROBLEM DESCRIPTIONThere is an XSS problem found in aMember. A hacker may inject some bad JavaScript to headers and it will be executed when you are viewing aMember CP -> Access Log, or aMember CP -> Error Log. Descibed thing may ONLY happen if: - a "hacker" really makes it; - you access aMember CP logs while the injected message appears; - the hacker uses received information to login into aMember CP as admin. It is impossible to hack your website and find out password without your invention. METHODS OF PROTECTIONMETHOD 1. SECURING EXISTING INSTALLATION BY REPLACING FILESPlease do the following:
https://www.amember.com/support/ METHOD 2. UPGRADE TO aMEMBER PRO 3.0.4 (NOT REQUIRED IF YOU FOLLOW METHOD 1)If you want to stay recent, you may download and upgrade to latest version from members area. Full changelog will be published in the forum within 48 hours after this notice. Please note, that CGI-Central staff is unable to make upgrades for free. Upgrade procedure described here. |
|
|
|
|
|
Copyright (C) 2005 AMEMBER.com. All Rights Reserved. Partners - Affiliate Program - Privacy policy - License agreement - Sales & Refund policy |
|