MyBB 1.6.12 Released – Security & Maintenance Release

MyBB 1.6.12 is now available from the MyBB website and is a security and maintenance release.

What’s added/changed in this version?

This release fixes 4 vulnerabilities and 10 reported issues causing incorrect functionality of MyBB. Please be aware that to be able to provide easy to manage updates not all issues have been fixed in this version.

  • Vulnerabilities:
    • Medium Risk: A SQL vulnerability when editing smilies in ACP – reported by ChALkeR
    • Medium Risk: A SQL vulnerability when deleting posts with Akismet in ACP – reported by ChALkeR
    • Medium Risk: A XSS vulnerability in video MyCode – reported by ChALkeR
    • Low Risk: A XSS vulnerability in smilie popup – reported by Spenzert
  • Bugs fixed:

Information on upgrading, template changes and language changes can be found on the Docs site.

Please note, that you do not need to run the upgrade script for this version.
There are no database schema changes in this version.

Upgrading from 1.6.11 and Other Versions

Before performing any upgrade please remember to backup your forum’s files and database and store them safely. If you have edited core files, including language files, please make sure you make a changelog for these changes so you can make them again (if necessary) once the upgrade is complete.

To upgrade, follow the Upgrading process. The upgrade script is not required. There are changes to 2 language files. No templates have been changed or added.

If you’re using MyBB 1.6.11

If you’re using MyBB 1.6.10 or lower

Reporting MyBB security vulnerabilities

If you think you’ve found a vulnerability in MyBB, we advise you not to publicly post it on these forums or publicly release information about it elsewhere until we’ve had time to prepare and release a patch.

As always, you can send through security related messages on the MyBB website from the Contact Us page or in our Private Inquiries forum – where you can start a new thread that only you and the MyBB Team can see.

Thanks,

MyBB Team

25 thoughts on “MyBB 1.6.12 Released – Security & Maintenance Release

  1. Did anyone fix the LOWER sql search on usernames logging in yet? It means it doesn’t use the index and causes 100% cpu issues on larger sites when spam bots try to login. There is no need for that query to be case sensitive as far as I’m aware

  2. Pingback: MyBB 1.6.12 gotowe - Polskie Wsparcie MyBB

  3. I applied the changed files to a 1.6.11 installation, but got an error saying that the board needed to be updated when trying to visit my forum or the ACP. After running the upgrade script (which was announced as not being necessary), I no longer get that error.

  4. Ugh, I was using 1.6.11 and used the changed files package, but MyBB still thinks it’s 1.6.11. The admin control panel keeps telling me I need to upgrade.

      • I was afraid someone would say that. Just to be sure, I unpacked the files to the proper directory for a third and fourth time. MyBB still indicates that it is 1.6.11 and the control panel indicates that there is still a newer version.

Comments are closed.