Follow glFusion on Facebook Follow glFusion on Twitter
Sign Up!
Login
Welcome to glFusion
Friday, March 12 2010 @ 01:18 AM CST
Share

glFusion v1.1.2 and earlier SQL Injection Issue

An additional SQL injection vulnerability has been identified in all current versions of glFusion that could allow an attacker to expose the password hash for any user on your site.  This could lead to an attacker successfully logging into your site using those compromised credentials.

All glFusion users should replace the lib-sessions.php source file with this updated version which will remove the vulnerability:

private/system/lib-sessions.zip

glFusion v1.1.3 has been released and includes all security fixes.

My Account





Sign up as a New User
Lost your password?

Want to Help?

Join the Dev Community today! Interested in helping out?
Join our Dev Community!

Support glFusion

Vote for glFusion at opensourcecms.com