Upgrade now to ImpressCMS 1.2.4 Security Release
The ImpressCMS Project announces an important update to the 1.2.x series, addressing 2 vulnerabilities recently discovered.
The first issue was with the imagemanager plugin for TinyMCE, allowing unauthorized creation of image categories. The second is a potential cross site scripting vulnerability in the quicksearch functionality of the ImpressCMS Persistable Framework. This vulnerability required elevated permissions and was only present in the administration area.
This issue has now been fixed in version 1.2.4. The ImpressCMS team urges everyone to upgrade their ImpressCMS installation as soon as possible.
URL:
http://www.christianwebresources.net/modules/planet/view.article.php/1624
Trackback: http://www.christianwebresources.net/modules/planet/trackback.php/1624
Trackback: http://www.christianwebresources.net/modules/planet/trackback.php/1624
The comments are owned by the poster. We aren't responsible for their content.