- Apr 23, 2012
- 2,864
- 5,878
Text -
Security Update: XenForo 2.0.11 Released
Today, we have released XenForo 2.0.11 to address a potential security vulnerability. The vulnerability is a cross site scripting (XSS) issue that can allow malicious scripts and HTML to be injected into the page, potentially leading to data theft or unauthenticated access. Specifically, the issue relates to specially crafted text entered into messages and output using the structured text system (used in profile posts and comments).
We recommend that all customers running XenForo 2.0.x upgrade to 2.0.11 as soon as possible. XenForo 1.x is not affected and no action need be taken by customers running versions prior to 2.0.x.
Customers with an active license may download 2.0.11 from their customer area. Full details for how to install and upgrade XenForo can be found in the XenForo Manual.
For customers who would prefer not to perform the full upgrade, a patch is available from the 2.0.11 release announcement.
Release Announcement - https://xenforo.com/community/threads/xenforo-2-0-11-released-security-fix.156690/