When someone is looking for a mechanic, it can be hard to know whom you can trust to do the work using the best practices available for a fair price. Finding a System Administrator often carries some similar challenges. Certifications are one way to show that a Sysadmin is up to date on the best way to secure data and administer servers. cPanel is now offering SafeAdmin certification as a way to appraise a technician’s existing set of skills, representing …
Archive for CMS
If you’ve been to any of our conferences before, chances are you’ve attended Game Night on the final night. WebPros Summit 2019 promises to be the biggest and best conference yet, and we would be remiss in not bringing in the best of the best for arguably the most fun evening event of the Summit. Introducing the reimagined, bigger and badder GAME NIGHT. 21st Century Digital Game As always, we’re bringing in some of the …
Upcoming Changes to Let’s Encrypt Plugin
Earlier this year, Let’s Encrypt announced the end of life (EOL) plan for their original API. Starting this November, they will no longer allow new account registrations through the original API. After the original API reaches EOL, new account registrations must use Let’s Encrypt’s new API. Because of this, cPanel is migrating its Let’s Encrypt plugin to use that new API instead of the old API. Why change now? If we do not update our plugin, we …
Need help asking your boss to attend WebPros Summit?
The upcoming WebPros Summit 2019 is almost upon us! In talking with different members of the community, a common theme pops up from those who want to attend. “How do I convince my boss/company/employer that we/I should attend the WebPros Summit?” Never fear, we have a solution for you! Take this handy pre-formatted letter and simply replace the text that goes in [these boxes]. There’s plenty of value to attending the Summit this year, and …
Joomla 3.9.11 is now available. This is a security fix release for the 3.x series of Joomla which addresses one security vulnerability and contains over 25 bug fixes and improvements.
[20190801] – Core – Hardening com_contact contact form
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Low
- Versions: 1.6.2 – 3.9.10
- Exploit type: Incorrect Access Control
- Reported Date: 2019-April-09
- Fixed Date: 2019-August-13
- CVE Number: CVE-2019-XXXXX
Description
Inadequate checks in com_contact could allowed mail submission in disabled forms.
Affected Installs
Joomla! CMS versions 1.6.2 – 3.9.10
Solution
Upgrade to version 3.9.11
Contact
The JSST at the Joomla! Security Centre.
You’ve probably heard that WordPress is open source software, and may know that it’s created and run by volunteers. WordPress enthusiasts share many examples of how WordPress changed people’s lives for the better. This monthly series shares some of those lesser-known, amazing stories. Meet Amanda Rush from Augusta, Georgia, USA. Amanda Rush is a WordPress […]
Summit /ˈsəmət/ (noun)- the highest level or degree attainable; the highest stage of development.This year the cPanel Conference is being transformed into the WebPros Summit. With the addition of cPanel to the WebPros family of companies, the natural progression for our annual conference was a combined conference. Partnering with the communities of Plesk, WHMCS, and SolusVM will increase the size and impact that an annual hosting conference has. Enter WebPros Summit 2019. With the power …
…in the great state of Texas, a software company offered unto its’ subjects a Feature Request Site where they could submit their feedback about the products it worked so diligently to create and support. This site was launched in October 2012 to great fanfare and fingers flew across keyboards from across all the lands as requests were submitted. Each person was allotted votes they could use to make their greatest wishes for cPanel known, …
This month has been characterized by exciting plans and big announcements – read on to find out what they are and what it all means for the future of the WordPress project. WordCamp Asia Announced The inaugural WordCamp Asia will be in Bangkok, Thailand, on February 21-23, 2020. This will be the first regional WordCamp […]
Today we announced a new partnership with our friends over at CloudLinux. Anyone who is gearing up to migrate from CentOS 6 to CentOS7 (and again from CentOS 7 to CentOS 8 in a few years) can now consider another option! cPanel & WHM Version 86: The last version to support CentOS 6 We are planning on carrying support for CentOS 6 until the next LTS version of cPanel & WHM, Version 86. Only one version …
Back in April, we released an experimental version of NGINX into the wild for cPanel users at large to test and play around with. The feedback we’ve received from you, the cPanel Community, has been great! For those of you that have been using the experimental version of NGINX, there have been several add-on features that have been requested we add to NGINX to make it more viable. While we’re still a long ways …
Hi. I’m Tabby. I joined the Community Team at cPanel in March 2019 as a Community Manager. I couldn’t be more excited about it if I tried, and I’ll tell you why; my entire career has led to this role. I’ve done so many weird and disparate things that from the outside, I’m sure when I tell folks that I was an award-winning music educator before I was a Community Manager, it makes no sense …
You’ve probably heard that WordPress is open source software, and may know that it’s created and run by volunteers. WordPress enthusiasts share many examples of how WordPress changed people’s lives for the better. This monthly series shares some of those lesser-known, amazing stories. Meet Ugyen Dorji from Bhutan Ugyen lives in Bhutan, a landlocked country […]
With the release of cPanel & WHM version 82 to CURRENT this week, we are adding several new UAPI modules and functions. These new functions replace several previously-deprecated cPanel API 1 functions. For a complete list of API calls that we’ve added so far, read our Guide to Replacing cPanel API 1 functions with UAPI equivalents documentation. Our goal is to provide a more seamless experience for anyone who integrates with cPanel & WHM. What is an API, and who uses …
Joomla 3.9.10 is now available. This is a bug fix release for the 3.x series of Joomla which addresses one bug introduced into 3.9.9, affecting template styles of multilingual web sites.
Joomla 3.9.9 is now available. This is a security fix release for the 3.x series of Joomla which addresses one security vulnerability and contains over 30 bug fixes and improvements.
[20190701] – Core – Filter attribute in subform fields allows remote code execution
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Low
- Versions: 3.9.7 – 3.9.8
- Exploit type: Remote Code Execution
- Reported Date: 2019-June-20
- Fixed Date: 2019-July-09
- CVE Number: TBA
Description
Inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option.
Affected Installs
Joomla! CMS versions 3.9.7 – 3.9.8
Solution
Upgrade to version 3.9.9
Contact
The JSST at the Joomla! Security Centre.
YOYOW Foundation Becomes a Platinum Global Sponsor of Joomla!
Late last week, we announced a new licensing and pricing structure for cPanel. This change was the result of several months of conversations and modeling to ensure we understood as many use cases for cPanel & WHM hosting as possible. In the days following our announcement, we have heard from many of our Partners, both online and on the phone, and the feedback has been clear. Our analysis of use cases was incomplete, …
June has certainly been a busy month in the WordPress community — aside from holding the largest WordPress event ever, the project has hit a number of significant milestones and published some big announcements this past month. A Wrap for WordCamp Europe 2019 WordCamp Europe 2019 took place on June 20-22. It was the largest […]
Today, we announced a new pricing and licensing structure to our Partners, Distributors, and our cPanel Store customers. Our pricing and licensing will now be standardized for all of our customers, be billed monthly, and include multiple Tiers. When cPanel defined its original pricing structure, some twenty plus years ago, servers were not as powerful as they are today. Thanks to constant innovation in the hardware sector and optimization in our software, we can now run hundreds …
cPanel Application Manager and App Deployment 101
Researching another piece I’ve been writing, I realized that I was grossly unfamiliar with a portion of the cPanel & WHM product. For a bit of background, I’ve been using cPanel & WHM for about nine years now, mostly from the end user and system administrator perspectives. Admittedly, I am not a developer, nor do I pretend to be one. Between you and me, I have immense respect for developers and the dark arts magic that …
WordPress 5.2.2 is now available! This maintenance release fixes 13 bugs and adds a little bit of polish to the Site Health feature that made its debut in 5.2. For more info, browse the full list of changes on Trac or check out the Version 5.2.2 documentation page. WordPress 5.2.2 is a short-cycle maintenance release. The next […]
Joomla 3.9.8 is now available. This is a bug fix release for the 3.x series of Joomla which addresses one bug introduced into 3.9.7 which affects web sites using the French Help Server.
Joomla 3.9.7 is now available. This is a security fix release for the 3.x series of Joomla which addresses three security vulnerabilities and contains over 40 bug fixes and improvements.
[20190603] – Core – ACL hardening of com_joomlaupdate
- Project: Joomla!
- SubProject: CMS
- Impact: Low
- Severity: Low
- Versions: 3.8.13 through 3.9.6
- Exploit type: Incorrect Access Control
- Reported Date: 2019-April-10
- Fixed Date: 2019-June-11
- CVE Number: CVE-2019-12764
Description
The update server URL of com_joomlaupdate can be manipulated by non Super-Admin users.
Affected Installs
Joomla! CMS versions 3.8.13 through 3.9.6
Solution
Upgrade to version 3.9.7
Contact
The JSST at the Joomla! Security Centre.
[20190602] – Core – XSS in subform field
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Low
- Versions: 3.6.0 through 3.9.6
- Exploit type: XSS
- Reported Date: 2019-January-01
- Fixed Date: 2019-June-11
- CVE Number: CVE-2019-12766
Description
The subform fieldtype does not sufficiently filter or validate input of subfields, this leads to XSS attack vectors.
Affected Installs
Joomla! CMS versions 3.6.0 through 3.9.6
Solution
Upgrade to version 3.9.7
Contact
The JSST at the Joomla! Security Centre.
[20190601] – Core – CSV injection in com_actionlogs
- Project: Joomla!
- SubProject: CMS
- Impact: Low
- Severity: Low
- Versions: 3.9.0 through 3.9.6
- Exploit type: CSV Injection
- Reported Date: 2019-April-29
- Fixed Date: 2019-June-11
- CVE Number: CVE-2019-12765
Description
The CSV export of com_actionslogs is vulnerable to CSV injection.
Affected Installs
Joomla! CMS versions 3.9.0 through 3.9.6
Solution
Upgrade to version 3.9.7
Contact
The JSST at the Joomla! Security Centre.
According to Statista, over 3 billion people across the world are expected to have some form of social media account by 2021. That’s 1/3 of the population of the entire planet. While social media use in the business world has been around for the better part of a decade, it has recently become an integral part of growing communities and building brand recognition. Companies use social media as customer outreach, to announce a new …