MyBB 1.6.13 Released – Security & Maintenance Release

MyBB 1.6.13 is now available from the MyBB website and is a security and maintenance release.

What’s added/changed in this version?

This release fixes 4 vulnerabilities and 38 reported issues causing incorrect functionality of MyBB. Please be aware that to be able to provide easy to manage updates not all issues have been fixed in this version.

  • Vulnerabilities:
    • Medium Risk: Possibility of executing PHP code through stylesheets – reported by TonyS
    • Medium Risk: Possibility of executing PHP code through language files – reported by Pirata Nervo
    • Low Risk: A XSS vulnerability in search system (CVE-2014-1840)
    • Low Risk: Potential weak random string generator reported by – reported by 1llusion
  • Bugs fixed:

Please view the 1.6.13 changes on the Docs site for more information about the changes in this version.

Please note, that you do need to run the upgrade script for this version.

Upgrading from 1.6.12 and Other Versions

Before performing any upgrade please remember to backup your forum’s files and database and store them safely. If you have edited core files, including language files, please make sure you make a changelog for these changes so you can make them again (if necessary) once the upgrade is complete.

To upgrade, follow the Upgrading process. The upgrade script is required. There are changes to 5 language files. 4 templates have been changed or added.

If you’re using MyBB 1.6.11 or lower

Reporting MyBB security vulnerabilities

If you think you’ve found a vulnerability in MyBB, we advise you not to publicly post it on these forums or publicly release information about it elsewhere until we’ve had time to prepare and release a patch.

As always, you can send through security related messages on the MyBB website from the Contact Us page or in our Private Inquiries forum – where you can start a new thread that only you and the MyBB Team can see.

Thanks,

MyBB Team

Note about updated package

Due to a minor issue with the original packages an updated package set has been released.

If you installed or updated your forums using either the full or changed files packages prior to 9:30 a.m. on April 27, 2014 GMT please download a fresh package from the links above and replace the following file:

admin/modules/style/themes.php

You do not need to run the installer or make any further changes. You can use the file verification tool to determine whether you have the latest package, the file above will appear to be modified if you need to download an updated copy.

We apologise of any inconvenience.

16 thoughts on “MyBB 1.6.13 Released – Security & Maintenance Release

  1. “If you’re using MyBB 1.6.12 or lower

    Download and use the full 1.6.13 Release Package”

    Should it not read if your using a version less than 1.6.12 you need to use the full package? Normally if your using the latest version (in this case 1.6.12) you can use the change package version which you show a link and download above what is quoted?

    Just want to clarify what i need to use before i upgrade my 1.6.12 version.

  2. Thanks for the update and the update’s update, it’s updated and everything looks up-to-date. Looking forward to the next update.

  3. Pingback: 4 Vulnerabilities and 38 Bugs Fixed with the Release of MyBB 1.6.13 - Hack3r.PW - +Positive Security

  4. Pingback: 4 Vulnerabilities and 38 Bugs Fixed with the Release of MyBB 1.6.13 | Tech Information

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s