amuck-landowner

WHMCS Security Advisory

peterw

New Member
Code:
Case 3492
Remove dependency on unserialize() for admin table sorting

=== Severity Level ===
Important

=== Description ===
Object Injection Attack.
An attacker, once authenticated into the admin area of the product, could leverage user input passed to unserialize() to execute arbitrary PHP.
 

MartinD

Retired Staff
Verified Provider
Retired Staff
Do a hard refresh or clear your cache.

Currency symbol issue too... that's resolved with some patches from WHMCS.
 

ComputerTrophy

New Member
In my opinion WHMCS should be contacting CloudFlare as well with vulnerability details so CloudFlare can develop their Web Application Firewall. Such a partnership could be great, since CloudFlare could block the vulnerabilities in the first hour before they're even patched.
 

KuJoe

Well-Known Member
Verified Provider
So the only security exploit that was patched was one that allows admin to run PHP code on my server? Considering all of the admins in my WHMCS have root access to the server already this is not a huge concern.
 
Last edited by a moderator:
  • Like
Reactions: scv

InertiaNetworks-John

Inertia Networks, LLC
Verified Provider
So the only security exploit that was patched was one that allows admin to run PHP code on my server? Considering all of the admins in my WHMCS have root access to the server already this is not a huge concern.
Very true, but you have to realize for bigger companies, this may not be the case.
 

Aldryic C'boas

The Pony
Very true, but you have to realize for bigger companies, this may not be the case.
Hell, we have a small staff, and it's not the case with us, either.  I'm the only one with full WHMCS privs (Fran doesn't even have a login, although he and I are the only two with keys on that box).  Though granted, we don't bring anyone onboard as staff unless we're willing to put a LOT of trust into them anyways.
 

Coastercraze

Top Thrill
Verified Provider
So the only security exploit that was patched was one that allows admin to run PHP code on my server? Considering all of the admins in my WHMCS have root access to the server already this is not a huge concern.
No there is more... Read the blog post.
 

nunim

VPS Junkie
I keep getting invalid token errors, mainly in Intelligent Search but I see them from time to time elsewhere. 
 

fapvps

New Member
Verified Provider
I'm very happy to see that they are working on the product they are selling. It was very frustrating to deal with the 0day exploits that came out recently. It is really a good thing that they are releasing the updates often. I'll gladly apply a weekly incremental patch to keep the billing system secure and as bug free as possible. I don't understand why people would complain about WHMCS releasing updates...People should complain if they don't release updates...
 
Top
amuck-landowner