Kunena 6.3.0 released

The Kunena team has announce the arrival of Kunena 6.3.0 [K 6.3.0] in stable which is now available for download as a native Joomla extension for J! 4.4.x/5.0.x/5.1.x. This version addresses most of the issues that were discovered in K 6.2 and issues discovered during the last development stages of K 6.3

Question Kunena 5.1.14 Released - Security update

More
4 years 8 months ago #1 by 810
The key distinctions of K 5.1.14 are:

1 Security fix -...

Introduction

The Kunena team is proud to announce the arrival of Kunena 5.1.14 [K5.1.14] which is now available for download as a native Joomla extension for Joomla 3.9.x. This version addresses most of the issues that were discovered in K 5.1 and issues discovered during the development stages of K 5.1.14. This update fixed 1 security issue.

We have Released K5.1.14 because of a 1 High Security issue

1 New feature to turn off "Re:" on subject names.

Read more...

Please Log in or Create an account to join the conversation.

More
4 years 7 months ago #2 by reufelss
Sorry but Iám new hier.

We have the cross site scripting problem. By abusing the vulnerability an attacker can store JavaScript in the database, which is stored in the title of the answer he or she wrote. The now stored XSS is executed every time a user enters the affected topic in the forum, which could therefore be triggered by any user of the system. Note that the XSS gets only executed if it is the latest answer of the topic.

Can you help us?

Attachment not found


Attachment not found

Please Log in or Create an account to join the conversation.

More
4 years 7 months ago #3 by 810
You should install the update, then the problem should be solved. If you run any issue, then please try the nightly build, its on our download page, on the bottom.

Please Log in or Create an account to join the conversation.

More
4 years 7 months ago #4 by reufelss
I have installed the update. Our Version is 5.1.14

Please Log in or Create an account to join the conversation.

More
4 years 7 months ago - 4 years 7 months ago #5 by reufelss
Hello, we have just installed version 5.1.15 DEV. Unfortunately, Java scripts, e.g. when replying to posts, can be execute in the header.
We testet it with the script "><script>alert(1)</script>
Last edit: 4 years 7 months ago by reufelss.

Please Log in or Create an account to join the conversation.

More
4 years 7 months ago #6 by rich
Please use the correct category for your problem. This category here is for official announcements and not for troubleshooting.

Please Log in or Create an account to join the conversation.

Time to create page: 0.524 seconds