1
Mamba
XOOPS 2.5.11.1 - security update for XOOPS 2.5.11

Resized Image


XOOPS 2.5.11.1 — security update for XOOPS 2.5.11

The XOOPS Development Team has released XOOPS 2.5.11.1, a security update for XOOPS 2.5.11. It changes only the input filter that XOOPS uses on request data. If your site runs XOOPS 2.5.11, please apply it.

DOWNLOAD: https://github.com/XOOPS/XoopsCore25/releases/tag/v2.5.11.1

What's fixed

XOOPS 2.5.11 bundles the XMF library, and its input filter (Xmf\FilterInput, which XoopsFilterInput builds on) now includes the fixes from XMF 1.2.32.1:

* Filtering always finishes: some input made the filter run until PHP hit its memory limit, so one request could take a page down. A value that does not settle after a fixed number of passes is now dropped. (GHSA-8j4x-8r8r-5jgw)
* Stricter tag and attribute checks: some tag and attribute patterns got through the filter. Tag and attribute names are now checked strictly, event-handler attributes are matched whatever their case, link schemes are checked after HTML entities are decoded, and stripped text keeps no partial tag. (GHSA-pf53-59r5-mhjv)

There are no database, template or language changes, and no new features. The fix keeps PHP 5.6 compatibility, so 2.5.11.1 runs on the same servers as 2.5.11.

How to update

From XOOPS 2.5.11 (recommended: the patch)
1. Download xoops-2.5.11-to-2.5.11.1-patch.zip from the release page
2. Back up your site files
3. Copy the contents of the zip's htdocs folder over your XOOPS root folder (the one that holds mainfile.php), keeping the folder paths. Two files are replaced:
class/libraries/vendor/xoops/xmf/src/FilterInput.php
include/version.php
4. That's it. You don't need to run the upgrade wizard. System Admin now shows XOOPS 2.5.11.1-Stable

New install, or a version older than 2.5.11
Use the full package (the source code zip on the release page) and follow the usual install or upgrade steps.

XOOPS 2.7
XOOPS 2.7.4 RC 2 already includes the same fixes through XMF 1.3.2. If you are planning a move to the 2.7 line, see github.com/XOOPS/XoopsCore27/releases.

Reporting issues
Please report problems at github.com/XOOPS/XoopsCore25/issues, with your PHP and MySQL versions. Security issues should be reported privately, as described in the repository's SECURITY.md, not in a public issue. Questions are welcome in the support forums.

Thank you
Thank you to the researchers who reported these issues responsibly and to everyone who reviewed and tested the fixes. And a standing thank-you to JetBrains for the complimentary PhpStorm licenses that power the core team's development.

The XOOPS Development Team
Support XOOPS => DONATE
Use 2.7.x | Docs | Modules | Bugs