Hello,
Short version, are there any security updates between EE 1.6.0 and the latest version.
Long version, My name is Jeremy, i recently volunteered to work with one of Australia’s larger not for profits, they currently use what seems to be a fairly old version of expression engine.
I noticed several security vulnerabilities (nothing necessarily to do with EE), and upon contacting the host found that there have been some problems over the yeras. I have immediately changed some permissions issues and various things, I am now reviewing the EE CMS. Its quite possible that even your old version of EE 1.6.0 had no issues and the security problems were solely related to permissions.
I found EE was running version 1.6.0 which seems quite old even by the standard of legacy stated on this web site. Are there any security releases which are important to be deployed which may have resulted in the vulnerabilities over the years.
Nextly, if there are updates, does the 7 site license this client has running EE for every state in australia entitle them to a secure new version, such as the 1.7.X series, or maybe even 2.X series. And would I be able to obtain this for free.
Thirdly, I know this comes under paid support but is it going to be a difficult migration, if you cant answer that I’ll wait until I have account details or work it out myself.
I really appreciate any help, this is for sick kids so if I am going outside normal support protocol because I am not logged in with their official account and I am not posting in technical support please consider just even a nudge in the right direction.