The second release candidate for WordPress 5.4 is now available! WordPress 5.4 is currently scheduled to be released on March 31 2020, and we need your help to get there—if you haven’t tried 5.4 yet, now is the time! There are two ways to test the WordPress 5.4 release candidate: Try the WordPress Beta Tester plugin (choose the “bleeding edge […]
Archive for security
[20200306] – Core – SQL injection in Featured Articles menu parameters
- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: Low
- Versions: 1.7.0-3.9.15
- Exploit type: SQL Injection
- Reported Date: 2020-March-9
- Fixed Date: 2020-March-10
- CVE Number: CVE-2020-10243
Description
The lack of type casting of a variable in SQL statement leads to a SQL injection vulnerability in the “Featured Articles” frontend menutype.
Affected Installs
Joomla! CMS versions 1.7.0 – 3.9.15
Solution
Upgrade to version 3.9.16
Contact
The JSST at the Joomla! Security Centre.
[20200305] – Core – Incorrect Access Control in com_fields SQL field
- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: Low
- Versions: 3.7.0-3.9.15
- Exploit type: Incorrect Access Control
- Reported Date: 2020-February-28
- Fixed Date: 2020-March-10
- CVE Number: CVE-2020-10239
Description
Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.
Affected Installs
Joomla! CMS versions 3.7.0 – 3.9.15
Solution
Upgrade to version 3.9.16
Contact
The JSST at the Joomla! Security Centre.
[20200304] – Core – Identifier collisions in com_users
- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: Low
- Versions: 3.0.0-3.9.15
- Exploit type: Other
- Reported Date: 2020-February-07
- Fixed Date: 2020-March-10
- CVE Number: CVE-2020-10240
Description
Missing length checks in the user table can lead to the creation of users with duplicate usernames and/or email addresses.
Affected Installs
Joomla! CMS versions 3.0.0 – 3.9.15
Solution
Upgrade to version 3.9.16
Contact
The JSST at the Joomla! Security Centre.
[20200303] – Core – Incorrect Access Control in com_templates
- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: Low
- Versions: 2.5.0-3.9.15
- Exploit type: Incorrect Access Control
- Reported Date: 2020-January-31
- Fixed Date: 2020-March-10
- CVE Number: CVE-2020-10238
Description
Various actions in com_templates lack the required ACL checks, leading to various potential attack vectors.
Affected Installs
Joomla! CMS versions 2.5.0 – 3.9.15
Solution
Upgrade to version 3.9.16
Contact
The JSST at the Joomla! Security Centre.
[20200302] – Core – XSS in Protostar and Beez3
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Low
- Versions: 3.0.0-3.9.15
- Exploit type: XSS
- Reported Date: 2020-February-24
- Fixed Date: 2020-March-10
- CVE Number: CVE-2020-10242
Description
Inadequate handling of CSS selectors in the Protostar and Beez3 JavaScript allow XSS attacks.
Affected Installs
Joomla! CMS versions 3.0.0 – 3.9.15
Solution
Upgrade to version 3.9.16
Contact
The JSST at the Joomla! Security Centre.
[20200301] – Core – CSRF in com_templates image actions
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Low
- Versions: 3.2.0-3.9.15
- Exploit type: CSRF
- Reported Date: 2020-February-06
- Fixed Date: 2020-March-10
- CVE Number: CVE-2020-10241
Description
Missing token checks in the image actions of com_templates causes CSRF vulnerabilities.
Affected Installs
Joomla! CMS versions 3.2.0 – 3.9.15
Solution
Upgrade to version 3.9.16
Contact
The JSST at the Joomla! Security Centre.
In the March edition of our “People of WordPress” series, you’ll find out how Mary Job grew from a timid, curious cat into a public speaker and organizer of WordPress Meetups and WordCamps.
The first release candidate for WordPress 5.4 is now available! This is an important milestone as we progress toward the WordPress 5.4 release date. “Release Candidate” means that the new version is ready for release, but with millions of users and thousands of plugins and themes, it’s possible something was missed. WordPress 5.4 is currently […]
Browsers on track to block 850,000 TLS 1.0 sites
More than 850,000 websites still rely on the outdated TLS 1.0 and TLS 1.1 protocols that are scheduled to be blocked by the majority of web browsers this month. These older versions of the Transport Layer Security protocol, which date back to 1999 and 2006, are vulnerable to numerous practical attacks that have been resolved in later versions. Among the sites still using these outdated setups are major banks, governments, news, and telecoms companies.
February 2020 was a busy month in the WordPress project! Most notably, there was an outpouring of sentiment in response to the unfortunate cancellation of WordCamp Asia. However, the team continues to work hard in the hopes of making WordCamp Asia 2021 happen. In addition, there were a number of releases and some exciting new […]
WordPress 5.4 Beta 3 is now available! This software is still in development, so we don’t recommend you run it on a production site. Consider setting up a test site to play with the new version. You can test the WordPress 5.4 beta in two ways: Try the WordPress Beta Tester plugin (choose “bleeding edge nightlies” […]
As mentioned in this post, Matt will host a livestream on February 22 during Bangkok daylight hours. He opened an invitation to any speaker who was affected by the cancellation, and the livestream will include the following fine people: Imran Sayed, Md Saif Hassan, Muhammad Muhsin, Nirav Mehta, Piccia Neri, Umar Draz, and Francesca Marano […]
Internet Explorer 11 End of Support in cPanel Version 88
cPanel continues to move towards a more modern user interface framework to provide the best product experience possible. That’s why we are going to start shifting away from Internet Explorer 11, starting with Version 88. This change not only offers a better user experience, but it also allows us to be more efficient in our development process. We are encouraging cPanel Partners and users to discontinue the use of IE11 as their primary web browser …
WordPress 5.4 Beta 2 is now available! This software is still in development, so we don’t recommend running it on a production site. Consider setting up a test site to play with the new version. You can test WordPress 5.4 beta 2 in two ways: Try the WordPress Beta Tester plugin (choose the “bleeding edge nightlies” option) Or download […]
You’ve probably heard that WordPress is open-source software, and may know that it’s created and run by volunteers. WordPress enthusiasts share many examples of how WordPress changed people’s lives for the better. This monthly series shares some of those lesser-known, amazing stories. The beginning In 1998, Kori created her very first HTML website. Her dad […]
WordCamp Asia Cancelled Due to COVID-19
I’ve arrived at the difficult decision to cancel the inaugural WordCamp Asia event, which was planned to take place in Bangkok on February 21st. The excitement and anticipation around this event have been huge, but there are too many unknowns around the health issues unfolding right now in the region to explicitly encourage a large […]
WordPress 5.4 Beta 1 is now available for testing! This software is still in development, so we don’t recommend running it on a production site. Consider setting up a test site to play with the new version. You can test the WordPress 5.4 beta in two ways: Try the WordPress Beta Tester plugin (choose the “bleeding edge nightlies” […]
ImunifyAV+ – Strengthen Your Site Security
Helping create a safer internet is an essential part of cPanel’s mission, and that’s why we began integrating security extensions right into our product. We started by offering Imunify360, a robust and comprehensive security suite, as a featured product in 2018. Then, in 2019, we integrated ImunifyAV into all cPanel & WHM servers. Now, with the release of cPanel & WHM Version 86, we are pleased to include ImunifyAV+ as a product that can be purchased …
Following an action-packed December, 2020 is off to a fine start with some new releases and announcements. Read on to find out what happened in the WordPress project in January. Release of Gutenberg 7.2 & 7.3 Gutenberg 7.2, the first Gutenberg release of 2020, was deployed on January 8th and included over 180 pull requests […]
cPanel & WHM LTS Named Tier Autofixer and You
Beginning in cPanel & WHM Version 86, the way we use the term “LTS” or Long Term Support in reference to our software is changing. We’re making this important change for several reasons, and we want to provide you with information to help you keep your servers secure and up to date. How cPanel’s Versioning and Tiers Work We’re making a change to our release methodology and update system, which will assist you in keeping your servers …
cPanel Store Now Offering SolusVM Licenses
We have begun offering SolusVM Master Enterprise licenses to Direct Store customers through the cPanel Store as an option for hypervisor users who wish to utilize the virtualization management software. SolusVM licenses are a new option to purchase, but aren’t a required installation or upgrade. If you’re interested in a control panel for a virtualized environment, read on to find out more. What is SolusVM? SolusVM is a GUI and API based VPS management system with support for platform virtualization tools such as
[20200103] – Core – XSS in com_actionlogs
- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: Low
- Versions: 3.9.0-3.9.14
- Exploit type: XSS
- Reported Date: 2019-December-25
- Fixed Date: 2020-January-28
- CVE Number: CVE-2020-xxxxx
Description
Inadequate escaping of usernames allow XSS attacks in com_actionlogs.
Affected Installs
Joomla! CMS versions 3.9.0 – 3.9.14
Solution
Upgrade to version 3.9.15
Contact
The JSST at the Joomla! Security Centre.
[20200102] – Core – CSRF com_templates LESS compiler
- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: Low
- Versions: 3.0.0-3.9.14
- Exploit type: CSRF
- Reported Date: 2019-December-18
- Fixed Date: 2020-January-28
- CVE Number: CVE-2020-xxxxx
Description
A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.
Affected Installs
Joomla! CMS versions 3.0.0 – 3.9.14
Solution
Upgrade to version 3.9.15
Contact
The JSST at the Joomla! Security Centre.
[20200101] – Core – CSRF in batch actions
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Low
- Versions: 3.0.0-3.9.14
- Exploit type: CSRF
- Reported Date: 2019-December-23
- Fixed Date: 2020-January-28
- CVE Number: CVE-2020-8419
Description
Missing token checks in the batch actions of various components causes CSRF vulnerabilities.
Affected Installs
Joomla! CMS versions 3.0.0 – 3.9.14
Solution
Upgrade to version 3.9.15
Contact
The JSST at the Joomla! Security Centre.
You’ve probably heard that WordPress is open-source software, and may know that it’s created and run by volunteers. WordPress enthusiasts share many examples of how WordPress changed people’s lives for the better. This monthly series shares some of those lesser-known, amazing stories. Meet Robert Cheleuka Robert is a self-taught graphic and motion designer turned web […]
WordPress Leaders Nominated for CMX Awards
Two members of the WordPress leadership team were nominated for excellent work in their field in the first ever Community Industry Awards. Andrea Middleton is nominated for Executive Leader of a Community Team and Josepha Haden Chomphosy is nominated for Community Professional of the Year. CMX is one of the largest professional organizations dedicated to […]
The new year is here and with it comes a new round of updates for cPanel & WHM®. While we’re just now rolling out Version 86, now is the time to take action. With the release of Version 88, we will start removing cPanel API 1 functionality, and any custom code or integrations using these calls will no longer work. Why is the API 1 functionality being removed? The cPanel API 1 system is outdated and …
As 2019 draws to a close and we look ahead to another exciting year let’s take a moment to review what the WordPress community achieved in December. WordPress 5.3.1 and 5.3.2 Releases The WordPress 5.3.1 security and maintenance release was announced on December 13. It features 46 fixes and enhancements. This version corrects four security […]
OpenSSL 1.1.1 and TLSv1.3 Beta Testing Open Call
We are looking for users to test drive TLSv1.3 and OpenSSL 1.1.1 with EasyApache 4 and cPanel. Read more if you’d like to take part in this test.