Netix Posted October 27, 2013 Share Posted October 27, 2013 Hello, i have got this email: Client ID: XXXX has requested to change his/her details as indicated below: Company Name: '' to 'AES_ENCRYPT(1,1), companyname=((SELECT GROUP_CONCAT(id,0x3a,username,0x3a,email,0x3a,password SEPARATOR 0x2c20) FROM tbladmins))' Default Payment Method: '' to '' If you are unhappy with any of the changes, you need to login and revert them - this is the only record of the old details. and when i am go to client details i see admin emails and encrypted passwords in company name filed of this client. Is this normal that field can run SQL query or there is problem with my configuration? Thanx 0 Quote Link to comment Share on other sites More sharing options...
TommyK Posted October 27, 2013 Share Posted October 27, 2013 You probably haven't applied the latest security updates and you should upgrade now. Also you should probably check what harm might have been caused. 0 Quote Link to comment Share on other sites More sharing options...
WHMCS CEO Matt Posted October 27, 2013 WHMCS CEO Share Posted October 27, 2013 This was patched against in the v5.2.9 release so in any version later than that it poses no risk. If you are running an earlier version please update as soon as possible as there's been a number of important security updates recently (http://blog.whmcs.com/) Matt 0 Quote Link to comment Share on other sites More sharing options...
Netix Posted October 27, 2013 Author Share Posted October 27, 2013 Thank you for fast replay. Version was 5.2.7 and now it is upgraded to latest version. 0 Quote Link to comment Share on other sites More sharing options...
DavidBee Posted October 27, 2013 Share Posted October 27, 2013 Thank you for fast replay.Version was 5.2.7 and now it is upgraded to latest version. Can't you see the red upgrade notice next to the version? Its really careless of you not to upgrade your billing system. 0 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.