ExpressionEngine CMS
Open, Free, Amazing

Thread

This is an archived forum and the content is probably no longer relevant, but is provided here for posterity.

The active forums are here.

Version 1.7.1 Build 20110520 Security and Maintenance Release

May 20, 2011 2:03pm

Subscribe [3]
  • #1 / May 20, 2011 2:03pm

    Robin Sowell

    13255 posts

    A security and maintenance release for 1.7.1 is now available for download.  The release addressed a critical bug where each member’s settings for ‘Enable Avatar’ and ‘Enable Signatures’ were reset to ‘No’ when preferences were updated in the control panel’s General Configuration page.  The release also addresses a security issue where an SQL injection was at least theoretically possible.  There are no known cases of a successful exploit and such an attack could only be executed by someone with control panel access and access to the admin area with “Can administrate general preferences”.

    Given the potential security exploit (however unlikely) and the chance for data loss, we decided a small, fast release to address these issues was in order.  This release is recommended for all users.

  • #2 / May 20, 2011 4:42pm

    municipal

    165 posts

    Is there anyway you could let us know which files changed just this one time? I have a lot of hacks (including all the language files) and just went through this three days ago with the previous update. Pretty please…? 😊

  • #3 / May 20, 2011 5:01pm

    Robin Sowell

    13255 posts

    😉  It’s the system/cp/cp.admin.php file.  Replace that and you’ll be fine.  For the build to be correct- replace core.system.php as well- but not doing so won’t hurt anything.

  • #4 / May 20, 2011 5:10pm

    municipal

    165 posts

    Thanks…much appreciated!

  • #5 / May 20, 2011 5:19pm

    Robin Sowell

    13255 posts

    Not a problem- this one really was a quick fix out the door.  Just did not want to take a chance on someone goofing up all of their members’ settings!

.(JavaScript must be enabled to view this email address)

ExpressionEngine News!

#eecms, #events, #releases