Written by Nick A.
Update 2: ERRATA: All sites should either update to CB 1.0.1 or correct a Joomla setting !The following mass email has just been sent (actually in progress) to all Joomlapolitans ...
Fellow Community Builder Website Masters,
The CB Core team over at joomlapolis.com has been working hard during the past 48 hours on a security release 1.0.1 of the CB suite following the discovery of a vulnerability present in 1.0 RC2 and 1.0 stable on weakly configured web-servers. We have decided to release it as a highly-recommended critical security and stability update, as we had one report this morning and another one this afternoon for 2 sites where it got exploited to change files. Your site needs urgent update to CB 1.0.1 if ALL of these PHP settings are met: CB 1.0.1 will be released in the next hours and will be available on http://www.joomlapolis.com and on the Community Builder project area on forge.joomla.org.
Everyone is urged to upgrade asap, a REAME file is included in the release as usual.
Sites with the settings above are in danger.
If you want to stop receiving future messages of this type just visit your contact info tab on your joomlapolis profile and click on the "Don't email me critical vulnerability fixes" checkbox.
Thank you,
The CB Team on Joomlapolis.com
| Discuss this article on the forums. (75 posts) |