JomSocial Blog
JomSocial team just released a security update for JomSocial 1.6 and JomSocial 1.5. This patch addresses an issue where attackers might be able to execute arbitrary javascript with a carefully crafted content. The patch will secure all exploitable holes in current and previous version of JomSocial.
We would recommend all of our customers to apply the patch immediately.
To install this patch:
1. Download the attached file and unzip it
2. Upload the files in 'frontend' folder to /components/com_community/
3. Upload the files in 'backend' folder to /administrator/components/com_community/
4. Upload the files in 'modules' folder to /modules/
5. Upload the files in 'plugins/plg_groups/groups.php' file to /plugins/community/
Download links:
JomSocial 1.6.288
JomSocial 1.5.248
JomSocial 1.2.206
Up to date, we haven't received any report on such attacks from live websites and this vulnerability is found by our internal security audit team.
Please take note that we have only tested the patches on the 1.6.288 , 1.5.248 and 1.2.206 releases. The patches have also been deployed in our latest stable release 1.6.289 which can be downloaded from your account area at http://jomsocial.com/download.html
28 Response(s)
Fatal error: Call to undefined method CFactory::unsetActiveProfile() in /home/absibm/public_html/plugins/user/jomsocialuser.php on line 53
Any smart advice?
Is this the correct link because JomSocial 1.2.206 patch is also linking to the same zip file.
Fatal error: Call to undefined method CToolbar::getToolBarGroupKey() in /home/mccth1/mccth.org/components/com_community/templates/default/toolbar.index.php on line 12
I'm also seeing this in the forums. I'd STRONGLY suggest backing up your working install first, as this is VERY frustrating.
JomSocial staff -- please help us out here...
I do appreciate the quick response in keeping us (and our social networks) all safe from evil hackers. :D
You can download JomSocail 1.6.289 from the member download area
Mine installation for example is one of the kind and i would probably had to spend another two weeks on applying all customizations again if i do clean upgrade to 289.