XOOPS 2.5.11.1 — security update for XOOPS 2.5.11The XOOPS Development Team has released
XOOPS 2.5.11.1, a security update for XOOPS 2.5.11. It changes only the input filter that XOOPS uses on request data. If your site runs XOOPS 2.5.11, please apply it.
DOWNLOAD:
https://github.com/XOOPS/XoopsCore25/releases/tag/v2.5.11.1What's fixedXOOPS 2.5.11 bundles the XMF library, and its input filter (
Xmf\FilterInput, which
XoopsFilterInput builds on) now includes the fixes from XMF 1.2.32.1:
*
Filtering always finishes: some input made the filter run until PHP hit its memory limit, so one request could take a page down. A value that does not settle after a fixed number of passes is now dropped. (
GHSA-8j4x-8r8r-5jgw)
*
Stricter tag and attribute checks: some tag and attribute patterns got through the filter. Tag and attribute names are now checked strictly, event-handler attributes are matched whatever their case, link schemes are checked after HTML entities are decoded, and stripped text keeps no partial tag. (
GHSA-pf53-59r5-mhjv)
There are no database, template or language changes, and no new features. The fix keeps PHP 5.6 compatibility, so 2.5.11.1 runs on the same servers as 2.5.11.
How to updateFrom XOOPS 2.5.11 (recommended: the patch)1. Download
xoops-2.5.11-to-2.5.11.1-patch.zip from the release page
2. Back up your site files
3. Copy the contents of the zip's
htdocs folder over your XOOPS root folder (the one that holds mainfile.php), keeping the folder paths. Two files are replaced:
class/libraries/vendor/xoops/xmf/src/FilterInput.php
include/version.php
4. That's it. You don't need to run the upgrade wizard. System Admin now shows
XOOPS 2.5.11.1-StableNew install, or a version older than 2.5.11Use the full package (the source code zip on the release page) and follow the usual install or upgrade steps.
XOOPS 2.7XOOPS 2.7.4 RC 2 already includes the same fixes through XMF 1.3.2. If you are planning a move to the 2.7 line, see
github.com/XOOPS/XoopsCore27/releases.
Reporting issuesPlease report problems at
github.com/XOOPS/XoopsCore25/issues, with your PHP and MySQL versions. Security issues should be reported privately, as described in the repository's SECURITY.md, not in a public issue. Questions are welcome in the
support forums.
Thank youThank you to the researchers who reported these issues responsibly and to everyone who reviewed and tested the fixes. And a standing thank-you to
JetBrains for the complimentary
PhpStorm licenses that power the core team's development.
The XOOPS Development Team