View Single Post
  #1  
Old 11-14-2013, 04:36 AM
 
carpeperdiem carpeperdiem is offline
 

X-Guru
  
Join Date: Jul 2006
Location: New York City, USA
Posts: 5,399
 

Default security-patch-2013-10-08

Dear X-Cart,

About a month ago, you dropped a security patch...

security-patch-2013-10-08

May I ask WHY there were no announcements, no emails, no posts or notices of any kind about this? May I ask how you expected users to learn about this security patch?

Quote:
IMPACT
- XSS vulnerability for the Product_Configurator(Product Wizard) module (<= 4.6.1);
- XSS vulnerability for the Feature_Comparison module (<= 4.6.0);
- In some cases, customers can view orders of other customers (<= 4.6.0);
- Hacker can gain full access to the store's Admin back end through the 'Hidden Categories' module (<=4.6.0);
- Potential XSS vulnerability for some modules and product catalogs in the Customer area (<=4.5.5);

SO -- does this mean that if we do not use these modules, we can skip it?

Product_Configurator
Feature_Comparison
Hidden Categories

Quote:
- Potential XSS vulnerability for some modules and product catalogs in the Customer area

What modules? Under what circumstances?

A thorough discussion of this patch would be appreciated.
__________________
xcart 4.5.4 gold+ w/x-payments 1.0.6; xcart gold 4.4.4
Reply With Quote