Geeklog 1.8.2sr1 and 2.0.0rc2
- Wednesday, February 20 2013 @ 05:40 am EST
- Contributed by: Dirk
- Views: 22,071
We have received two reports about security issues that affect Geeklog in both current versions, i.e. 1.8.2 and 2.0.0 (which is not officially out yet, but in release candidate state):
- High-Tech Bridge Security Research Lab reported an XSS in the calendar_type parameter in the Calendar plugin.
- Trustwave Spiderlabs reported XSS in the install script, the Configuration, as well as in the Admin interfaces for the Polls plugin and the Topic editor.
To address these issues, we are releasing Geeklog 1.8.2sr1 (complete archive; also available as an update from 1.8.2) and Geeklog 2.0.0rc2.