WHMCS has released new patches for the 4 and 5 series. These updates provide targeted changes to address security concerns with the WHMCS product. You are highly encouraged to update immediately.
WHMCS has rated these updates as including critical and important security impacts. Information on security ratings is available at http://go.whmcs.com/74/securitylevels.
The following versions of WHMCS address all known vulnerabilities:
The latest public releases of WHMCS are available inside our members area at https://www.whmcs.com/members/clientarea.php
Security Issue Information
The resolved security issues were all identified by Vlad C. of NetSec Interactive Solutions <http://safeornot.net>. There is no reason to believe that these vulnerabilities are known to the public. As such, WHMCS will only release limited information regarding the vulnerabilities at this time.
Once sufficient time has passed to allow WHMCS customers to update their installed software, WHMCS will release additional information regarding the nature of the security issues. These Targeted Security Releases and Patches address 6 vulnerabilities in WHMCS version 4.0, 4.1, 4.2, 4.3, 4.4, 4.5, 5.0, 5.1, and BETA 5.2. Additional, supplemental information is scheduled to be released April 9th, 2013.
WHMCS Version 4.x
Download and apply the appropriate patch files to protect against these vulnerabilities.
Patch files for affected versions of the 4.x series are located on the WHMCS site as itemized below.
4.0 series: http://www.whmcs.com/download/170/12mar2013patchv40
4.1 series: http://www.whmcs.com/download/174/12mar2013patchv41
4.2 series: http://www.whmcs.com/download/178/12mar2013patchv42
4.3 series: http://www.whmcs.com/download/182/12mar2013patchv43
4.4 series: http://www.whmcs.com/download/186/12mar2013patchv44
4.5 series: http://www.whmcs.com/download/190/12mar2013patchv45
To apply the patch, simply download the appropriate patch file specific to the WHMCS version you are running, extract the contents, and upload the files from the /whmcs/ folder to your installation.
No install or upgrade process is required.
WHMCS Version 5.x
Download and apply the appropriate full-version of WHMCS to protect against these vulnerabilities.
Full-versions for the affected version of the 5.x series are located in the WHMCS members area download section, under your license details.
When updating from v5.2.0 BETA to v5.2.1 STABLE, you must perform an upgrade. The upgrade process is described here: http://docs.whmcs.com/Upgrading#Performing_an_Upgrade
When updating from v5.0.3 or v5.1.3, the upgrade process is not required. To apply the full-version, simply download the appropriate file specific to the WHMCS version you are running, extract the contents, and upload the files from the /whmcs/ folder to your installation.
*This Security Advisory is in the process of being emailed to all active license holders.*
Date: Tuesday, March 12, 2013
Posted by Matt on Tuesday, March 12th, 2013