Introduction

The Kunena team is proud to announce the arrival of Kunena 5.1.14 [K5.1.14] which is now available for download as a native Joomla extension for Joomla 3.9.x. This version addresses most of the issues that were discovered in K 5.1 and issues discovered during the development stages of K 5.1.14. This update fixed 1 security issue.

We have Released K5.1.14 because of a 1 High Security issue

1 New feature to turn off "Re:" on subject names.

The key distinctions of K 5.1.14 are:

  • 1 Security fix - High
  • Fix canonical in search (#6536)
  • Add ID to category counter (#6537)
  • Fix errors on DiscussionForumPosting (#6544)
  • Add option to disable Re on subject
  • same length subject on item as on index
  • Find the full changes: Here.

XSS Topic - High vulnerability

[20190813] - Core - XSS Vulnerability

• Project: Kunena
• SubProject: Forum Core: Bbcode
• Severity: High
• Versions: 5.x through 5.1.14
• Exploit type: XSS
• Reported by: Andrey Skuratov | FBK | CyberSecurity
• Reported Date: 2019-08-13 16:04
• Fixed Date: 2019-08-13 19:00
• Release Date: 2019-08-13 19:15
• Vel url:

Description:
BBcode leads to XSS vulnerability.

Affected Installs

Kunena versions 5.0.x through 5.1.14

Solution

Upgrade to version 5.1.14

Contact

This email address is being protected from spambots. You need JavaScript enabled to view it..


Download

K 5.1.14 is available for download on the download page.

Log in to comment

rich replied the topic:
4 years 7 months ago
rich's Avatar
Please use the correct category for your problem. This category here is for official announcements and not for troubleshooting.
reufelss replied the topic:
4 years 7 months ago
reufelss's Avatar
Hello, we have just installed version 5.1.15 DEV. Unfortunately, Java scripts, e.g. when replying to posts, can be execute in the header.
We testet it with the script "><script>alert(1)</script>
reufelss replied the topic:
4 years 7 months ago
reufelss's Avatar
I have installed the update. Our Version is 5.1.14
810 replied the topic:
4 years 7 months ago
810's Avatar
You should install the update, then the problem should be solved. If you run any issue, then please try the nightly build, its on our download page, on the bottom.
reufelss replied the topic:
4 years 7 months ago
reufelss's Avatar
Sorry but Iám new hier.

We have the cross site scripting problem. By abusing the vulnerability an attacker can store JavaScript in the database, which is stored in the title of the answer he or she wrote. The now stored XSS is executed every time a user enters the affected topic in the forum, which could therefore be triggered by any user of the system. Note that the XSS gets only executed if it is the latest answer of the topic.

Can you help us?

Attachment not found


Attachment not found