Jump to content

Security Update 2023-06-20 - Lifetime owners excluded?


Recommended Posts

WHMCS have just sent a notice regarding an exploit that affects all versions of WHMCS. 

Sadly, it seems that owned license holders are exempt from receiving critical patches?

I was a happy paying customer who paid their $99 per year for support and updates until the massive shift, and now I've been left in the dark.

Can WHMCS staff kindly review this considering the impact of this matter, had this exploit been identified during the time in which I had paid for support a patch would have been released and further to this, the fact that the exploit affects all versions of whmcs means that this exploit existed when I had active support.

Link to comment
Share on other sites

We also have a 7.10.3 install - as the way the contacts/accounts are managed just doesn’t work for us in the newer releases.  The later releases caused all sorts of issues with customers changing email addresses and passwords, locking themselves out of portal accounts.

We just need/needed a 1 user 1 login system, which we were/are unable to achieve with later versions - last time we tried.

Really stuck now 😕

Edited by SVCode
Link to comment
Share on other sites

  • WHMCS Support Manager

Targeted Security Releases have been published for our Current and Long Term Support versions (8.7 and 8.6)

Owned License holders will be able to auto-update to 8.7.3 or 8.6.2, if your Support & Updates was active during those releases.

We have also exceeded our Long Term Support policy by providing a patch for 8.5, because it recently reached End of Life. Users can apply if your Support & Updates was active during the 8.5 release.

 

We do not recommend running an End of Life version of WHMCS for this reason.

However on this occasion, if you're running an older End of Life version, please contact support and we can assist: https://www.whmcs.com/submit-a-ticket/

Link to comment
Share on other sites

3 minutes ago, tokenuser said:

Is there a way to get a patch for 8.4.1? It's the last version we were able to download with our "lifetime" license. 

You got lucky with your renewal date, ours is a few versions before but still within version 8

Link to comment
Share on other sites

  • 2 weeks later...

After applying this patch (early 8x version), Stripe payments are "uncaptured" at the gateway and WHMCS offers the clients just "Oops, something went wrong", so they try a few more times before opening a ticket. Anyone else notice oddness in this? the timing of the issue began immediately after applying the patch for us.

Link to comment
Share on other sites

They sent me the patch, then replied back later with the following:

"A defect has been identified in the Security Update 2023-06-20 patch provided for End of Life versions of WHMCS, which causes an error during payment captures made using the Stripe payment gateway."

I was then sent an updated version of the patch, that supposedly corrected this issue.  I do not use Stripe, so I'm not able to test that part.

 

Edited by SeanP
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated