WebsiteBaker Logo
  • *
  • Templates
  • Help
  • Add-ons
  • Download
  • Home
*
Welcome, Guest. Please login or register.

Login with username, password and session length
 

News


WebsiteBaker 2.13.10 Security Update is now available!


R.I.P Dietmar (luisehahne) and thank you for all your valuable work for WB
https://forum.websitebaker.org/index.php/topic,32355.0.html


* Support WebsiteBaker

Your donations will help to:

  • Pay for our dedicated server
  • Pay for domain registration
  • and much more!

You can donate by clicking on the button below.


  • Home
  • Help
  • Search
  • Login
  • Register

  • WebsiteBaker Community Forum »
  • WebsiteBaker »
  • General Announcements »
  • WebsiteBaker 2.13.10 Security Update
  • Print
Pages: [1]   Go Down

Author Topic: WebsiteBaker 2.13.10 Security Update  (Read 15 times)

Offline dbs

  • Betatester
  • **
  • Posts: 8983
  • Gender: Male
  • tioz4ever
    • WebsiteBaker - jQuery-Plugins - Module - Droplets - Tests
WebsiteBaker 2.13.10 Security Update
« on: Today at 09:41:58 AM »
WebsiteBaker 2.13.10 Security Update

DOWNLOAD:
- WebsiteBaker 2.13.10 Full Package: https://addon.WebsiteBaker.org/en/browse-add-ons/?id=0CD2C876
  New install / für Neuinstallationen und reguläre Updates

- WebsiteBaker 2.13.10 Security Update for WB 2.13.9: https://addon.WebsiteBaker.org/en/browse-add-ons/?id=022BA186
  Upgrade 2.13.9 / für bestehende WebsiteBaker-2.13.9-Installationen
----------------------------------------------------------------------------------------------------------------------------

Hello WebsiteBaker community,  (Deutsch weiter unten)
we have released WebsiteBaker 2.13.10 as an important security update for WebsiteBaker 2.13.x.
Two security vulnerabilities were responsibly reported to us by an independent security researcher. We would like to thank the researcher for the responsible disclosure and the cooperation.
The reported issues could allow remote code execution after successful exploitation. However, exploitation requires a valid WebsiteBaker administrator login. This means that the vulnerabilities cannot be used by an anonymous visitor without backend access. Nevertheless, websites with compromised, shared, weak, or reused administrator credentials could be at risk.
WebsiteBaker 2.13.10 includes security hardening and CodeGuard (new) protection improvements for areas such as:

- Droplets
- add-on/module installation
- template installation
- language file installation
- media uploads
- media ZIP extraction
- backend security checks

We strongly recommend that all WebsiteBaker 2.13.x users update to WebsiteBaker 2.13.10.

As always, please make a full backup of your files and database before updating.
For additional safety, we also recommend checking administrator accounts, using strong unique passwords, and removing unused administrator accounts.

-------------
Compatibility note for custom Droplets, add-ons, and templates
  • The new security checks may block or deactivate custom Droplets, modules, templates, language files, or uploaded files if they contain code patterns that are considered unsafe.
  • This is intentional. Regular WebsiteBaker installations and well-structured add-ons/templates should usually continue to work normally. However, older custom Droplets, self-made modules, or custom templates may need small adjustments if they use direct system calls, dynamic PHP function calls, executable upload tricks, unsafe SVG content, or similar patterns.
  • After the update, please check your installed Droplets, custom add-ons, and templates in the backend. If something is blocked by CodeGuard, the backend will show a message with a CodeGuard ID that can be used for support feedback.
-------------

The WebsiteBaker Team


### DEUTSCH ########################################################

Hallo WebsiteBaker-Community,

wir haben WebsiteBaker 2.13.10 als wichtiges Security Update für die WebsiteBaker-2.13.x-Serie veröffentlicht.

Uns wurden von einem unabhängigen Security Researcher zwei Sicherheitslücken verantwortungsvoll gemeldet. Wir bedanken uns ausdrücklich für die verantwortungsvolle Meldung und die Zusammenarbeit.

Die gemeldeten Schwachstellen konnten nach erfolgreicher Ausnutzung eine Ausführung von Code auf dem Server ermöglichen. Für die Ausnutzung ist jedoch ein gültiger WebsiteBaker-Administratorzugang erforderlich. Die Schwachstellen können also nicht direkt von anonymen Besuchern ohne Backend-Zugang ausgenutzt werden. Trotzdem können Installationen gefährdet sein, wenn Administratorzugäng e kompromittiert wurden oder schwache, gemeinsam genutzte oder wiederverwendete Passwörter verwendet werden.

WebsiteBaker 2.13.10 enthält Sicherheitsverbesse rungen und CodeGuard-Schutzmaßnahmen unter anderem für:

- Droplets
- Add-on-/Modulinstallation
- Template-Installation
- Sprachdatei-Installation
- Media-Uploads
- Entpacken von Media-ZIP-Dateien
- Backend-Sicherheitsprüfungen

Wir empfehlen allen Nutzern der WebsiteBaker-2.13.x-Serie dringend, auf WebsiteBaker 2.13.10 zu aktualisieren.

Bitte erstellt vor dem Update wie immer ein vollständiges Backup der Dateien und der Datenbank.
Zusätzlich empfehlen wir, Administratorzugäng e zu prüfen, starke individuelle Passwörter zu verwenden und nicht mehr benötigte Administratorzugäng e zu entfernen.
-------------------
Hinweis zu eigenen Droplets, Add-ons und Templates
  • Die neuen Sicherheitsprüfunge n können eigene Droplets, Module, Templates, Sprachdateien oder hochgeladene Dateien blockieren oder deaktivieren, wenn sie Code-Muster enthalten, die als unsicher eingestuft werden.
  • Das ist beabsichtigt. Normale WebsiteBaker-Installationen und sauber aufgebaute Add-ons/Templates sollten in der Regel weiterhin funktionieren. Ältere eigene Droplets, selbst erstellte Module oder eigene Templates müssen aber eventuell leicht angepasst werden, wenn sie direkte Systemaufrufe, dynamische PHP-Funktionsaufrufe, ausführbare Upload-Tricks, unsichere SVG-Inhalte oder ähnliche Muster verwenden.
  • Bitte prüft nach dem Update eure installierten Droplets, eigenen Add-ons und Templates im Backend. Wenn etwas durch CodeGuard blockiert wird, zeigt das Backend eine Meldung mit einer CodeGuard-ID an, die für Rückmeldungen im Support verwendet werden kann.
-------------------

Das WebsiteBaker-Team
« Last Edit: Today at 09:49:53 AM by dbs »
Logged
https://onkel-franky.de

  • Print
Pages: [1]   Go Up
  • WebsiteBaker Community Forum »
  • WebsiteBaker »
  • General Announcements »
  • WebsiteBaker 2.13.10 Security Update
 

  • SMF 2.0.19 | SMF © 2017, Simple Machines
  • XHTML
  • RSS
  • WAP2