Leaking personally identifiable information is serious and could cause legal problems for providers in parts of the world with sensible laws on data breaches.This isnt a really big issue, but it does give people the ability to get name/address/phone number from other customers.
It isnt as big as SQLI, and can be avoided with the disable of mass pay. So no, it's not as big of an issue as the first few were this month.Leaking personally identifiable information is serious and could cause legal problems for providers in parts of the world with sensible laws on data breaches.
Free market at work...Let's all chill out and relax: they're fixing it.
Now, the difference here is that the Blesta team is actively working on everything. They're participating in forums. They're making changes that you can see.
Blesta might not be the immediate replacement, but it's coming along nicely otherwise.
The flow of setting up products is so different coming from whmcs. On top of that, adding a product that it can't push a signal somewhere to provision seems stupid difficult. There's no "none" module but instead "universal" that seems to freak out at having nothing to do. I may need to read more but first impression based on that was bad. If it doesn't have a module you're really expected to write one or make it fit the universal one, not just manually provision your products.Fuck this shit. Anyone moved to Blesta? Does it work well? I'm considering it...
I'll give you a dollar if you can figure out how to add an addon to an existing product. :XThe flow of setting up products is so different coming from whmcs. On top of that, adding a product that it can't push a signal somewhere to provision seems stupid difficult. There's no "none" module but instead "universal" that seems to freak out at having nothing to do. I may need to read more but first impression based on that was bad. If it doesn't have a module you're really expected to write one or make it fit the universal one, not just manually provision your products.
If they ever actually fix their problems.I'm beginning to wonder how many more times localhost will need to publicly release exploits on WHMCS before they actually consider an external audit and programmers that are not a complete joke.
there is a difference between "not too bad" and "i'm going to reimplement register_globals badly myself, a feature that was removed from PHP core for being too insecure" and "i'm going to write my own version of mysql_query that doesn't actually sanitise anything or escape anything instead of using pdo"Wow, all the hate for WHMCS... I can pretty much guarantee that once Blesta becomes mainstream they will find issues with it as well. Nothing is ever 100% safe, unless you coded it yourself and YOU did all the security and did an external audit...
Just be patient. Update as soon as the patches come out and report issues to WHMCS.
Stop all the bitching and complaining and wanting to jump ship, because you know damn good and well that you ain't going anywhere! lol I had to wake up this morning and patch 3 WHMCS installs... :| Heh... It's all in a days work...
It'll get better just takes time.