3.8.7 security concern

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • sailnet
    Senior Member
    • Jan 2006
    • 171
    • 3.5.x

    3.8.7 security concern

    I received this message today from one of my forum members.

    comments?

    I'm an internally facing security architect for an Internet company, but I'm also a forum member.


    While I was trying to post a message, I noticed that angle-brackets were not escaped in forum output, yielding an XSS Vulnerability.


    If you compose a post containing: (LEFT_ANGLE_BRACKET)img src="/" onerror="alert(1)"(RIGHT_ANGLE_BRACKET) and then preview it, the javascript executes. You'll need to convert the brackets to actual brackets and remove the parentheses to try it out.


    I did not (and will not) attempt to submit the test post, I just previewed it. If submitting the post works, this puts your users at risk.


    I'm not looking for credit here, I just want to be safe while participating in the forums. I want my fellow users to be safe too.
  • Amaury
    Senior Member
    • Mar 2012
    • 1807
    • 4.2.X

    #2
    Make sure you have the latest patch installed for vBulletin 3.8.7.
    Former vBulletin user

    Comment

    • sailnet
      Senior Member
      • Jan 2006
      • 171
      • 3.5.x

      #3
      can I just download the files that need to be patched/replaced?

      and my support expired in 9/10 - what exactly do I need to purchase in order to download 3.8.7.PL3

      I'm running 3.8.6 Patch Level 1.

      thanks in advance.

      Comment

      • Loco.M
        Senior Member
        • Mar 2005
        • 4319
        • 3.5.x

        #4
        Originally posted by sailnet
        what exactly do I need to purchase in order to download 3.8.7.PL3

        I'm running 3.8.6 Patch Level 1.

        Upgrade your license if you don't have access to it.
        -- Web Developer for hire
        ---Online Marketing Tools and Articles

        Comment

        • sailnet
          Senior Member
          • Jan 2006
          • 171
          • 3.5.x

          #5
          Originally posted by Loco.M
          Upgrade your license if you don't have access to it.

          these appear to be my only options - which one do I choose?

          Mobile Suite Renewal (vB3/vB4 Only)

          Renew your current vB3/vB4 Mobile Suite. Please note that this product is for older vBulletin versions only, it will not work with vBulletin 5.

          $99.00/Year





          Support

          • Forum Support
            Included in license cost
          • One Month Phone and Ticket Support
            $49.00/Month
          • Annual Phone and Ticket Support
            $199.00/Year








          NoProfessional Installation/Upgrade

          Professional Install/Upgrade only includes vanilla install with no customization
          $149.00





          NoBranding-free Option

          Comment

          • Loco.M
            Senior Member
            • Mar 2005
            • 4319
            • 3.5.x

            #6
            none of those

            The one you'll want will be Upgrade: USD$209.00
            If you don't see that, you might want to contact [email protected]
            -- Web Developer for hire
            ---Online Marketing Tools and Articles

            Comment

            • eJM
              Senior Member
              • Sep 2004
              • 916
              • 3.8.x

              #7
              If you are already running 3.8.7, as your subject title implies, then you should be able to just download the patch file (https://members.vbulletin.com/patches.php) and follow the instructions here: https://www.vbulletin.com/forum/cont...atch-Your-Site

              Jim
              PS: Never mind. I see in post #3 you said you were running 3.8.6 Patch Level 1. Why'd you title the thread 3.8.7?
              Last edited by eJM; Thu 6 Dec '12, 11:51pm.
              If my post was helpful to you, please take the time to register at my forum and ask a question you've always wanted to know about floors.
              www.TheFloorPro.com

              Comment

              • Wayne Luke
                vBulletin Technical Support Lead
                • Aug 2000
                • 74111

                #8
                Edit the forum where this occurred within the Forum Manager in the Admin CP. Remove the permission for "Allow HTML". It is an option and we ship it with the option off. We encourage Administrators not to enable it. Some do anyway.
                Translations provided by Google.

                Wayne Luke
                The Rabid Badger - a vBulletin Cloud demonstration site.
                vBulletin 5 API

                Comment

                widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                Working...