Announcement

Collapse
No announcement yet.

vBulletin 3.8.1 PL1, 3.7.5 PL1 and 3.6.12 PL1 Released

Collapse
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • vBulletin 3.8.1 PL1, 3.7.5 PL1 and 3.6.12 PL1 Released

    vBulletin 3.8.1 PL1 / 3.7.5 PL1 / 3.6.12 PL1

    An XSS flaw within the editor controls has recently been discovered. This could allow an attacker to carry out an action as a user or obtain access to a user's account. To resolve this issue, it has been necessary to release a patch level version of the active versions of vBulletin.

    The upgrade process is the same as previous patch level releases - simply download the patch from the Members Area, extract the files and upload to your webserver, overwriting the existing files. There is no upgrade script required.

    As with all security-based releases, we recommend that all customers upgrade as soon as possible in order to prevent any potential damage resulting from the flaw being exploited.


    Upgrading from 3.8.1, 3.7.5 or 3.6.12

    If you are already running the latest version of the 3.6, 3.7 or 3.8 branch, the process you will be required to follow to make your board immune to this flaw is very simple.

    There is no need to run an upgrade script if you are already running the latest version.

    Visit the Patches section of the vBulletin Members' Area and download the patch for the version you are using, then extract the files from the archive you downloaded, then upload the files to your board via FTP etc., overwriting the existing files. This will update your version to the PL1 release.


    Upgrading from an earlier version

    If you are not already running the latest version of 3.6, 3.7 or 3.8, you should download the latest version from the Members' Area and perform an upgrade as normal.

    Full instructions for upgrading vBulletin are available here.


    Download vBulletin 3.8.1 PL1 / 3.7.5 PL1 / 3.6.12 PL1

    As usual, the version released today is available for all customers with valid, active licenses to download from the vBulletin Members' Area.

    vBulletin Members Area
    Scott MacVicar

    My Blog | Twitter

  • #2
    Please note that each patch zip file contains just two files that need to be uploaded:

    misc.php
    includes/version_vbulletin.php
    Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
    Change CKEditor Colors to Match Style (for 4.1.4 and above)

    Steve Machol Photography


    Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


    Comment


    • #3
      There is some confusion regarding the 'Path Level' designation. Please note that if you have uploaded the two files correctly, the Admin CP will show that you are running one of the following versions:

      Admin Control Panel (vBulletin 3.8.1 Patch Level 1)
      Admin Control Panel (vBulletin 3.7.5. Patch Level 1)
      Admin Control Panel (vBulletin 3.6.12 Patch Level 1)

      However the 'Patch Level 1' will not show in the footer on the forums.
      Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
      Change CKEditor Colors to Match Style (for 4.1.4 and above)

      Steve Machol Photography


      Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


      Comment

      Related Topics

      Collapse

      Working...
      X