10
My apologies. I'm still a little lost on this one.
According to a previous post, before the exploit could take place I would need to:
1. be logged in to the site as admin
2. click on an evil link sent to me in email
Is the above correct? If so, just for the sake of asking, how would said evil person get my email address? The XOOPS site I manage is a paid membership site and not open to just anyone so any member emailing me directly would be a trusted source. Regardless, my email address is not public, only a contact form is available.
If the above is not correct, please help me understand. This all seems a bit complex for me.
Last question - does this exploit include all versions or only 1.63? What about prior versions?
Thanks,
Hope