Invision Power Services Update
We are releasing a patch for IP.Board 3.4.x and 3.3.x that resolves multiple potential vulnerabilities. This update resolves several issues that we have been notified about in the share links, poll, uploads and IP.Chat systems. Ref. Source 8
Invision Power Services has recently introduced another layer of security by changing the passwords of everyone and requiring that certain questions be answered. According to Invision Power Services:
Invision Power Services
IPB is releasing IP.Board 3.4.7 today as a maintenance release to fix commonly reported issues and to consolidate security updates since 3.4.6 was released.
Issues fixed in this version:
Internet Explorer 11 Copy/Paste Issue
Facebook Profile Photos Not Loading
Incoming Email Piping throws an error
Terms of use link on registration broken
All security patches since last released are bundled in this version
Updates to Facebook Connect integration to support API Version 2.1 Ref. Source 2
Releasing patches for IP.Board 3.3.x and IP.Board 3.4.x to address two issues recently reported to us.
It has been brought to our attention that certain PHP configurations allow for a potential SQL injection vulnerability. Although this exploit requires some knowledge of your configuration and for certain files to be web-readable, we felt it important to release an update.
Additionally, it has been brought to our attention that it may be possible to send attachments via the email classes which would ordinarily be removed. Ref. Source 3