MyBB 1.8.19
18 September 2018
MyBB version 1.8.19 is now available.
Upgrading to MyBB 1.8.19
MyBB 1.8.19 can be upgraded to (or installed) using any of Installatron's products. Use Installatron's optional Automatic Update feature to automatically apply MyBB updates as new versions are released, or use Installatron's Clone feature to duplicate an existing MyBB install to test the 1.8.19 upgrade prior to applying it live. Get started managing your MyBB installations with Installatron
What's New in MyBB 1.8.19
This is a security and maintenance release for MyBB.
Security
- High risk: Email field SQL Injection — reported by StefanT
- Medium risk: Video MyCode Persistent XSS in Visual Editor — reported by Numan OZDEMIR of InfinitumIT
- Low risk: Insufficient permission check in User CP's attachment management — reported by StefanT
- Low risk: Insufficient email address verification — reported by StefanT
Bug Fixes
- #3429 All smilies should be shown on the full list
- #3428 Missing database inserts for engines other than MySQL
- #3415 Quick reply auto-subscribes users
- #3412 Inconsistent Styling of Restore Button
- #3410 Undefined/null values can be passed to my_hash_equals() on forum password check
- #3409 my_hash_equals() definition can be missing when evoking for password-protected forums
- #3397 Custom Profile Fields - Certain characters not escaped
- #3393 grammar issue in upgrade script