Introduction

The Kunena team is proud to announce the arrival of Kunena 5.1.5 [K5.1.5] which is now available for download as a native Joomla extension for Joomla 3.8.x. This version addresses most of the issues that were discovered in K 5.1 and issues discovered during the development stages of K 5.1.5. This update fixes also 2 low security issues.

The key distinctions of K 5.1.5 are:

  • 2 Security fixes - Low
  • Correct bootstrap loading on option
  • attachment symbol shows fancybox content
  • 2 enchaments: fancybox and fontawesome updates
  • Find the full changes: Here.

Posting Topic - low vulnerability

[20181010] - Core -

• Project: Kunena
• SubProject: Forum Core
• Severity: LOW
• Versions: 3.0 through 5.1.4
• Exploit type: Save Topic Privileges
• Reported by: sshcli
• Reported Date: 2018-10-10
• Fixed Date: 2018-10-10
• Release Date: 2018-10-14
• Joomla VEL: Joomla Vel

Description:
User can have Post privileges on a first category. In some cases with some settings.

Affected Installs

Kunena versions 3.0.0 through 5.1.4 (Kunena 5.1.5 is not affected)

Solution

Upgrade to version 5.1.5

Contact

This email address is being protected from spambots. You need JavaScript enabled to view it..


Low vulnerability

[20181012] - Core -

• Project: Kunena
• SubProject: Forum Core
• Severity: LOW
• Versions: 3.0 through 5.1.4
• Exploit type: none
• Reported by: Georgios Papadakis
• Reported Date: 2018-10-12
• Fixed Date: 2018-10-12
• Release Date: 2018-10-14
• Joomla VEL: Joomla Vel

Description:
This issue has been reported to the JSST but at it is not exploitable the JSST decided to patch it in this public tracker PR. Thanks to the reporter: @ggppdk See: Joomla Github.

Affected Installs

Kunena versions 3.0.0 through 5.1.4 (Kunena 5.1.5 is not affected)

Solution

Upgrade to version 5.1.5

Contact

This email address is being protected from spambots. You need JavaScript enabled to view it..


Download

K 5.1.5 is available for download on the download page.

Log in to comment

amazingreviews replied the topic: #1 1 month 1 week ago
all the best great achievement
mikerotec's Avatar
mikerotec replied the topic: #2 1 month 3 weeks ago
Changelog is missing... where is the changelog?