Author Topic: XSS Vulnerability Fix for v1.15 to v1.2.7  (Read 4370 times)

Offline Tomato Joe

  • Newbie
  • *
  • Posts: 29
  • Karma: +1/-0
    • View Profile
XSS Vulnerability Fix for v1.15 to v1.2.7
« on: July 20, 2016, 11:31:29 AM »
I made the fix below: 

XSS Vulnerability Fix for v1.15 to v1.2.7
Message status:
notice
Date:
06/15/2016 03:24:39 PM
Number of repetitions:
113
If you run AbanteCart version 1.1.5 to 1.2.7, we suggest that you apply the fix provided in the link :
http://forum.abantecart.com/index.php/topic,4727.0.html

but now I am getting this error message AND assume it related as I've never had this error until I made this fix.

Incorrect config.php file permissions
Message status:
warning
Date:
07/20/2016 09:22:29 AM
Number of repetitions:
86
/home/tomatojo/public_html/system/config.php file needs to be set to read and execute modes to keep it secured from editing!

SHOULD I REVERT BACK TO THE INSTALLED SETTING ??   

THANK YOU, JOE LEIST

Offline Basara

  • Administrator
  • Hero Member
  • *****
  • Posts: 5791
  • Karma: +274/-2
    • View Profile
Re: XSS Vulnerability Fix for v1.15 to v1.2.7
« Reply #1 on: July 21, 2016, 01:18:50 AM »
Hello.

It is very easy to improve file permission of the config.php file. Login to your Cpanel filemanager of FTP and change it to 644 or 444 see http://docs.abantecart.com/pages/tips/troubleshooting.html#permissions

Offline Tomato Joe

  • Newbie
  • *
  • Posts: 29
  • Karma: +1/-0
    • View Profile
Re: XSS Vulnerability Fix for v1.15 to v1.2.7
« Reply #2 on: July 21, 2016, 08:57:11 AM »
They were already changed to 0644.   Not sure why the error / notice then. 

Offline Basara

  • Administrator
  • Hero Member
  • *****
  • Posts: 5791
  • Karma: +274/-2
    • View Profile
Re: XSS Vulnerability Fix for v1.15 to v1.2.7
« Reply #3 on: July 21, 2016, 09:13:08 AM »
They were already changed to 0644.   Not sure why the error / notice then.

On some servers you need to set even 440. So change and remove this error from messages

 

Powered by SMFPacks Social Login Mod