Security Fix -- Please Read

31 views
Skip to first unread message

Andrew Darby

unread,
Jan 4, 2018, 9:28:33 AM1/4/18
to subjec...@googlegroups.com
Hi all,

It was pointed out to us that there is a possible SQL Injection issue in the "forgot password" functionality.  Please replace these two files with ones from the master branch on GitHub:

a) forgot password page
https://github.com/subjectsplus/SubjectsPlus/blob/master/control/forgotpassword.php

b) staff class

It is unlikely that you have localized either file, but if you are running a version earlier than 4, I can't promise it will work--you might just want to remove that forgot password page altogether.

Thanks to Talha for pointing this out!

Andrew
Reply all
Reply to author
Forward
0 new messages