MyBB 1.6.12 is now available from the MyBB website and is a security and maintenance release.
What’s added/changed in this version?
This release fixes 4 vulnerabilities and 10 reported issues causing incorrect functionality of MyBB. Please be aware that to be able to provide easy to manage updates not all issues have been fixed in this version.
- Medium Risk: A SQL vulnerability when editing smilies in ACP – reported by ChALkeR
- Medium Risk: A SQL vulnerability when deleting posts with Akismet in ACP – reported by ChALkeR
- Medium Risk: A XSS vulnerability in video MyCode – reported by ChALkeR
- Low Risk: A XSS vulnerability in smilie popup – reported by Spenzert
- Bugs fixed:
- MyCode parser adds new lines since 1.6.11
- Some plugins throwing errors due to usage of unsupported language file calls since 1.6.11
- Uploading attachments may fail when safe mode is enabled
- Promotion task option “weeks” doesn’t work properly
- Issue with queries not being executed in the correct order on logout
- #2196 Thread Prefix altered via Tamper Data
- #2251 Reputation doesn’t carry over when merging users
- #2267 See other’s posts in a “see own post forum” through archive
- #2275 Mod Log error when posting new thread
- Adding support for 4-Byte UTF-8 Unicode Encoding in MySQLWhen MySQL 5.5.3 or above is used a new option to convert the tables to 4-Byte UTF-8 Unicode Encoding is available in the “UTF-8 Conversion” page in the Admin Control Panel. This allows to store unicode characters with 4 bytes. If you don’t know what we are talking about you probably don’t need it. PgSQL and SQLite can store such characters by default.
Information on upgrading, template changes and language changes can be found on the Docs site.
Please note, that you do not need to run the upgrade script for this version.
There are no database schema changes in this version.
Upgrading from 1.6.11 and Other Versions
Before performing any upgrade please remember to backup your forum’s files and database and store them safely. If you have edited core files, including language files, please make sure you make a changelog for these changes so you can make them again (if necessary) once the upgrade is complete.
To upgrade, follow the Upgrading process. The upgrade script is not required. There are changes to 2 language files. No templates have been changed or added.
If you’re using MyBB 1.6.11
- Download and use the Changed Files Package (MD5: e39fbb0a8fcea856ed533c7d68869226)
- Follow the Docs Upgrading Instructions
If you’re using MyBB 1.6.10 or lower
Reporting MyBB security vulnerabilities
If you think you’ve found a vulnerability in MyBB, we advise you not to publicly post it on these forums or publicly release information about it elsewhere until we’ve had time to prepare and release a patch.
As always, you can send through security related messages on the MyBB website from the Contact Us page or in our Private Inquiries forum – where you can start a new thread that only you and the MyBB Team can see.