sentq Posted December 26, 2016 Share Posted December 26, 2016 there is a vulnerability discovered in PHPMailer, WHMCS v7.1 use (v5.2.16) the critical vulnerability (CVE-2016-10033) allows an attacker to remotely execute arbitrary code in the context of the web server and compromise the target web application. All versions of PHPMailer before the critical release of PHPMailer 5.2.18 are affected, so web administrators and developers are strongly recommended to update to the patched release. http://thehackernews.com/2016/12/phpmailer-security.html 0 Quote Link to comment Share on other sites More sharing options...
zomex Posted December 27, 2016 Share Posted December 27, 2016 Let's hope WHMCS see this thread quickly 0 Quote Link to comment Share on other sites More sharing options...
wsa Posted December 27, 2016 Share Posted December 27, 2016 Maybe sent a ticket to them 0 Quote Link to comment Share on other sites More sharing options...
twhiting9275 Posted December 27, 2016 Share Posted December 27, 2016 Yeah, opening a forum thread for critical issues, not exactly the fastest way to get a response 0 Quote Link to comment Share on other sites More sharing options...
WHMCS ChrisD Posted December 27, 2016 Share Posted December 27, 2016 Hey Everyone, Our development team is aware of and investigating the impact of this on our code base. They will then determine the appropriate response. As soon as I have more information, I will update this thread. 0 Quote Link to comment Share on other sites More sharing options...
sentq Posted December 27, 2016 Author Share Posted December 27, 2016 The idea of opening this thread is to keep WHMCS users informed so they can update manually if WHMCS didn't release patch/fix specially in this time of the year. 0 Quote Link to comment Share on other sites More sharing options...
WHMCS Sean Posted December 27, 2016 Share Posted December 27, 2016 Here is an update from our development team: The WHMCS development team has reviewed the recent changes to PHPMailer and the related information regarding CVE-2016-10033. While at this time we do not believe the deficiency in PHPMailer is exposed in WHMCS due to our own validation of user input, this CVE represents a serious issue for PHPMailer and therefore to mitigate any undiscovered risk we intend to deliver updates to PHPMailer for all versions of WHMCS in active and long term support. We anticipate delivering updates for WHMCS 7.x within the next 48 hours, and 6.2 and 6.3 shortly therafter. 0 Quote Link to comment Share on other sites More sharing options...
WHMCS Nate Posted December 29, 2016 Share Posted December 29, 2016 Hello, We have released updated builds that contain version 5.2.21 of PHPMailer. You can learn more on our blog: http://blog.whmcs.com/?t=123166 Have a great day, Nate C 0 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.