Announcing CMS Made Simple 1.1.4.1

Project Announcements. This is read-only, as in... not for problems/bugs/feature request.
Post Reply
Ted
Power Poster
Power Poster
Posts: 3329
Joined: Fri Jun 11, 2004 6:58 pm

Announcing CMS Made Simple 1.1.4.1

Post by Ted »

The ChangeLog looks a little something like this:

Version 1.1.4.1 "Taga" -- October 07 2007
-----------------
- Fix one issue in adodb_lite that cropped up after release

Version 1.1.4 "Taga" -- October 07 2007
-----------------
- Fixes an XSS issue in the anchor tag
- Fixes an XSS issue in listtags
- Adds a permission check to adduser.php
- More fixes for potential security issues with adodb_lite
- Added a permission check to view the admin log


Sorry for everyone that got 1.1.4.  Sometimes we jump the gun a little bit when there is pressure to get a security release out into everyone's hands.  It's best that it was on a Sunday (and a holiday in some areas of the world), so hopefully not too many people were affected.  If you were, I apologize.

Thanks!
Ted
Pierre M.

Re: Announcing CMS Made Simple 1.1.4.1

Post by Pierre M. »

Hello,

is there any information about the security breaches ? I'd like to know if some filtering rules can prevent them or if there is a way to improve the filter.
Of course I can wait for people having upgraded before exploits are revealed.

Pierre M.
kwsutherland

Re: Announcing CMS Made Simple 1.1.4.1

Post by kwsutherland »

Fantastic! CMS Made Simple just keeps getting better and better.

Props to Ted and the rest of the development team - Safety & security are crucial for content-managed sites, so I can't say enough how greatly I appreciate everyone behind CMSMS taking the time & consideration to address issues and release updates.

8) Again, fantastic work... keep it up!
Knuzen

Re: Announcing CMS Made Simple 1.1.4.1

Post by Knuzen »

Ted wrote: The ChangeLog looks a little something like this:

Version 1.1.4.1 "Taga" -- October 07 2007
-----------------
- Fix one issue in adodb_lite that cropped up after release

so far so good, but since several days I've installed 1.1.3.1 and filled in a lot of content-pages.

What should I do now? Is there any instruction, which files have to be changed, because I'm afraid to destroy my content, my database or installation. On the other hand I like to be update with any security patches.
RonnyK
Support Guru
Support Guru
Posts: 4962
Joined: Wed Oct 25, 2006 8:29 pm

Re: Announcing CMS Made Simple 1.1.4.1

Post by RonnyK »

Knuzen,

the diff-file to go from 1.1.3.1 to 1.1.4.1 is just a file-release, no DB-changes are made. Even if that was the case, the upgrade-script wouldnt destroy content.

After having made a BACKUP, you can just transfer the files of the diff-version over your files and you're on 1.1.4.1.

Ronny
Knuzen

Re: Announcing CMS Made Simple 1.1.4.1

Post by Knuzen »

Ronny,

I didn't see or know about the diff-Upgrade 1.1.3.1 to 1.1.4.1, I'm sorry for that,
I was just a little confused this morning.
Now I have transfered the diff-files over my content and everythings works well, like before,
which makes me glad.
:) Thanks!
Post Reply

Return to “Announcements”