Upgrade to Joomla 3.8.8 Today

More
10 months 3 days ago - 10 months 3 days ago #194 by Dom Cassone (dcassone)
As you all know by now, I am a nag about keeping your software up to date. So don't make me nag you, do the upgrade! :)



Joomla 3.8.8 is now available. This is a security release which addresses 9 security vulnerabilities, contains over 50 bug fixes, and includes various security-related improvements.

What's in 3.8.8?

Joomla 3.8.8 addresses 9 security vulnerabilities/hardenings and several bugs, including:
Security Issues Fixed

Low Priority - Core - ACL violation in access levels (affecting Joomla 2.5.0 through 3.8.7) More information »
Low Priority - Core - Add phar files to the upload blacklist (affecting Joomla 2.5.0 through 3.8.7) More information »
Moderate Priority - Core - Information Disclosure about unpublished tags (affecting Joomla 3.1.0 through 3.8.7) More information »
Low Priority - Core - Installer leaks plain text password to local user (affecting Joomla 3.0.0 through 3.8.7) More information »
Moderate Priority - Core - XSS Vulnerabilities & additional hardening (affecting Joomla 3.0.0 through 3.8.7) More information »
Low Priority - Core - Filter field in com_fields allows remote code execution (affecting Joomla 3.7.0 through 3.8.7) More information »
Low Priority - Core - Session deletion race condition (affecting Joomla 3.0.0 through 3.8.7) More information »
Low Priority - Core - Possible XSS attack in the redirect method (affecting Joomla 3.2.1 through 3.8.7) More information »
Low Priority - Core - XSS vulnerability in the media manager (affecting Joomla 1.5.0 through 3.8.7) More information »
Please see the documentation wiki for the security recommendations for updated sites.
More details about the session deletion race condition are available on the Developer Network site.
Bug fixes and Improvements

Miscellaneous accessibility improvements for the Backend
Updated CodeMirror to 5.37 and various improvements
Improved handling of numeric user group names
[com_content] Filter by no author
Added support for PHP 7.3’s is_countable function
Sending passwords by email disabled by default for new installs

PS - If you are hosting with us, or have a site that we manage for you, your site has already been upgraded to Joomla 3.8.4! All part of our secure managed hosting solution. For more information, reply to this post or email us at This email address is being protected from spambots. You need JavaScript enabled to view it.
Last edit: 10 months 3 days ago by Dom Cassone (dcassone).

Please Log in to join the conversation.

Time to create page: 0.636 seconds

Connect with us

Twitter
JoomFuse Forum
Joomla Community Magazine
Facebook

© Copyright 2013-2017 Zacaw Enterprises Inc. All rights reserved.
JoomFuse is not affiliated with or endorsed by Joomla.org or Open Source Matters. Logos are copyright by the respective companies and used with permission.

Comodo Secure SSL
Infusionsoft Certified Consultant and Partner Infusionsoft Certified Developer