WordPress 5.0 Beta 4 is now available! This software is still in development, so we don’t recommend you run it on a production site. Consider setting up a test site to play with the new version. There are two ways to test the WordPress 5.0 Beta: try the WordPress Beta Tester plugin (you’ll want “bleeding edge nightlies”), or […]
Archive for CMS
WordPress 5.0 Beta 3 is now available! This software is still in development, so we don’t recommend you run it on a production site. Consider setting up a test site to play with the new version. There are two ways to test the WordPress 5.0 Beta: try the WordPress Beta Tester plugin (you’ll want “bleeding edge nightlies”), or […]
To keep everyone aware of big projects and efforts across WordPress contributor teams, I’ve reached out to each team’s listed representatives. I asked each of them to share their Top Priority (and when they hope for it to be completed), as well as their biggest Wins and Worries. Have questions? I’ve included a link to […]
Teams across the WordPress project are working hard to make sure everything is ready for the upcoming release of WordPress 5.0. Find out what’s going on and how you can get involved. The Plan for WordPress 5.0 Early this month, the planned release schedule was announced for WordPress 5.0, which was updated a few weeks […]
It’s a good day for the Joomla Project, as today we proudly announce the release of Joomla 3.9 – ‘The Privacy Tool Suite’ – marking the tenth minor release in the 3.x series.
WordPress 5.0 Beta 2 is now available! This software is still in development, so we don’t recommend you run it on a production site. Consider setting up a test site to play with the new version. There are two ways to test the WordPress 5.0 Beta: try the WordPress Beta Tester plugin (you’ll want “bleeding edge nightlies”), or […]
WordPress 5.0 Beta 1 is now available! This software is still in development, so we don’t recommend you run it on a production site. Consider setting up a test site to play with the new version, and if you are using an existing test site be sure to update the Gutenberg plugin to v4.1. There are […]
If you’ve ever logged in to WHM as a root-level user, you’ve assuredly seen a box with a notification of a new or improved feature. This dialogue box is known as the “Feature Showcase,” and has allowed us at cPanel to present information about changes to cPanel & WHM. Since its creation, the Feature Showcase was only available for use by cPanel. However, we’ve made some changes to the functionality of the Feature Showcase …
How to Build a cPanel Hosting Environment on Amazon AWS
Let’s say you need to find hosting for multiple web applications with cPanel backend access so clients cannot access each other’s backends. What can you do to create a secure hosting environment without paying for several different hosting accounts? Why not host it yourself?! Disclaimer: If you have one or two lightweight websites, this probably isn’t the most cost effective route to go, however, if you are currently paying to host several websites and have …
[20181005] – Core – CSRF hardening in com_installer
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Low
- Versions: 2.5.0 through 3.8.12
- Exploit type: CSRF
- Reported Date: 2018-September-26
- Fixed Date: 2018-October-02
- CVE Number: CVE-2018-17858
Description
Added additional CSRF hardening in com_installer actions in the backend.
Affected Installs
Joomla! CMS versions 2.5.0 through 3.8.12
Solution
Upgrade to version 3.8.13
Contact
The JSST at the Joomla! Security Centre.
[20181004] – Core – ACL Violation in com_users for the admin verification
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Low
- Versions: 1.5.0 through 3.8.12
- Exploit type: ACL Violation
- Reported Date: 2017-December-27
- Fixed Date: 2018-October-02
- CVE Number: CVE-2018-17855
Description
In case that an attacker gets access to the mail account of an user who can approve admin verifications in the registration process he can activate himself.
Affected Installs
Joomla! CMS versions 1.5.0 through 3.8.12
Solution
Upgrade to version 3.8.13
Contact
The JSST at the Joomla! Security Centre.
[20181003] – Core – Access level Violation in com_tags
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Low
- Versions: 3.1.0 through 3.8.12
- Exploit type: ACL Violation
- Reported Date: 2018-June-20
- Fixed Date: 2018-October-02
- CVE Number: CVE-2018-17857
Description
Inadequate checks on the tags search fields can lead to an access level violation.
Affected Installs
Joomla! CMS versions 3.1.0 through 3.8.12
Solution
Upgrade to version 3.8.13
Contact
The JSST at the Joomla! Security Centre.
[20181002] – Core – Inadequate default access level for com_joomlaupdate
- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: Low
- Versions: 2.5.4 through 3.8.12
- Exploit type: Object Injection
- Reported Date: 2018-June-21
- Fixed Date: 2018-October-02
- CVE Number: CVE-2018-17856
Description
Joomla’s com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled access of Administrator-level users to access com_joomlaupdate and trigger a code execution.
Affected Installs
Joomla! CMS versions 2.5.4 through 3.8.12
Solution
Upgrade to version 3.8.13
Contact
The JSST at the Joomla! Security Centre.
Joomla 3.8.13 is now available. This is a security release for the 3.x series of Joomla which addresses 5 security vulnerabilities.
[20181001] – Core – Hardening com_contact contact form
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Low
- Versions: 2.5.0 through 3.8.12
- Exploit type: Incorrect Access Control
- Reported Date: 2018-September-17
- Fixed Date: 2018-October-02
- CVE Number: CVE-2018-17859
Description
Inadequate checks in com_contact could allowed mail submission in disabled forms.
Affected Installs
Joomla! CMS versions 2.5.0 through 3.8.12
Solution
Upgrade to version 3.8.13
Contact
The JSST at the Joomla! Security Centre.
The end of the cPanel Conference always triggers a mixture of feelings for me. The completion of the project means a lot of pride, and there’s a huge amount of relief, but it’s also bitter-sweet to know it’ll be a whole year before we get together again. To everyone that attended, sponsored, or exhibited at the 2018 cPanel Conference, thank you! We do this for you, and you continue to make it worth it. A …
Today is the first day of the 2018 cPanel Conference. We’re in the middle of setting everything up right now, getting ready to open up conference check-in and registration, and anticipating tonight’s networking party at Chapman and Kirby. We’ve spent the last 12 months planning this year’s conference, and we are ready to rock! Return of the Lab! This year the cPanel Lab is returning. In case you are unfamiliar, the cPanel Lab is a collection of …
The Month in WordPress: September 2018
The new WordPress editor continues to be a major focus for all WordPress contribution teams. Read on to find out some more about their work, as well as everything else that has been happening around the community this past month. Further Enhancements to the New WordPress Editor Active development continues on Gutenberg, the new editing […]
There are a lot of things we are looking forward to at this year’s conference. Engaging talks, fantastic networking sessions, super cool swag, and of course, some of the best evening events in the industry. We are bringing it back to our hometown of Houston, TX and we cannot wait to give you the grand tour! We have so much in store for our attendees that we’ve put together this checklist. By the time you all …
Earlier this year one of our technical analysts, Peter Elsner, wrote a tutorial on how to get the most from cPanel’s technical support. It hits on everything you should provide to our support team, but it is a great resource for any support request you submit to any team. A support team wants to solve your problem as much as you want to get it resolved, and clear information up front helps to …
Red alert, shields up – The work of the Joomla Security Team
A CMS-powered website has all the ingredients for an IT security nightmare: it is publicly accessible, it’s running on powerful machines with great connectivity and the underlying system is used countless times around the globe, making it an attractive target for attackers.
The Joomla Security Strike Team (JSST) is working hard to make sure that this nightmare doesn’t become reality for Joomla users!
Check out Halon, a new sponsor at this year’s cPanel Conference!
This is a guest blog post provided by the Halon Team! Halon is a first-time exhibitor of the annual cPanel Conference. —————- Are your customers spending time in spam-folders? Try Halon instead Halon is happy to announce that we will sponsor the cPanel conference for the first time. We have been here before but only as visitors. From what we have understood, a significant part of our target group is here which makes our presence …
Ready for cPanel & WHM Version Certification 2018?
cPanel Conference time is closing in steadily, with only 18 days left until the big event. Here on the cPanel University team, we’re continuing our tradition of offering a special certification. This certification is only available to those lucky folks that will be attending the conference in-person, who successfully complete a comprehensive exam. This exam covers the latest and greatest features and changes made over the past year’s worth of cPanel & WHM releases. Last …
Renaming Proxy Subdomains to Service Domains
In cPanel & WHM version 76, which we expect to be in EDGE this week, we renamed “Proxy Subdomains” to “Service Subdomains” due to improvements we are making under the hood. Let’s talk about where they came from, and why we’re changing their name! What are Proxy Subdomains? Proxy subdomains allow users to connect indirectly to the cPanel & WHM login pages. Rather than opening example.com:2083, they can open cpanel.example.com. Proxy subdomains have two primary uses for hosting providers …
The WHMCS team is incredibly excited to be sponsoring and taking part in cPanel Conference for another year. Thanks to our special relationship with cPanel, the cPanel conference provides a unique opportunity to connect with important partners and vendors that are part of the cPanel ecosystem and has proven itself to be a great event for bringing together people from all over the industry. The conference is taking place in our …
Welcome to the Land Where it Just Don’t Stop
This year cPanel has chosen its home base of Houston, Texas as the location for its annual conference. What makes the city so great? Let me tell you the ways! The Music! In his seminal 1998 Hip-Hop classic “Tops Drop,” rapper Fat Pat extolled on the virtues of living in the south Texas city of Houston- including its particular blend of “3rd Coast” hip-hop, the “Slab Culture” and the other general braggadocios claims made about …
Asking your boss to send you to #cPConf
Dear [Name of the world’s best boss], cPanel is having their annual conference from October 1st through October 3rd, and I think it would be very beneficial to the company for me to attend. As you know, cPanel has significantly increased the speed with which they develop new features and release new versions. They’ve released four new major versions each of the last three years. Increasing my knowledge of the cPanel & WHM software is …
Why use a multi-layered approach to securing web servers (LAB at the cPanel conference)
This is a guest blog post provided by the CloudLinux Team! CloudLinux is an alumni sponsor of the annual cPanel Conference. —————- We all know that layered security is best practice in server protection. Imunify360, the all-encompassing security product from CloudLinux, recently made significant feature upgrades to its multi-layered security. It has improved the way it stops malware and protects your Linux servers from nearly all kinds of attacks.
The Beginning is The End is The Beginning (of EasyApache)
As most of you are aware, EasyApache3 (EA3) is going to End of Life status as of December 2018. Moving to EOL status means that if you are still running EA3 by the time v78 is released, you will not be able to upgrade to the newest version of cPanel & WHM. The life cycle of EA3 over the next few cPanel releases will play out as follows: Advisements in version 72: warnings have been added to …
A true story of a mission impossible.
This is a guest post from Tim Hollis, VP of Operations at JetApps! JetApps has returned this year to exhibit at the cPanel Conference, October 1st – 3rd in Houston, Texas. If you haven’t already, take a look at the agenda, book your room (discounted rates apply until September 9th!), and get registered! As a software company, nothing makes us happier here at JetApps than hearing stories of how JetBackup has …