Security Fix! EasyDiscuss 4.1.11 Released! Addressed possible unrestricted file upload vulnerability 🔐

Helpdesk

I noticed on my live site a user was able to register with a not@registered.com email address. When looking deeper i noticed this use was able to create an Easy Social account yet not complete any of the form details which is impossible.

So i loaded up the dev site, Last user registered with ID 1045. Nothing out of the ordinary here

I updated and checked each time after updating Easy Social and Discuss, everything is fine

As soon as i updated Payplans from Launcher Package, as per screen shot you have added a new user.

I presume this is a misstep and not intended?
Attachments (1)
Attachments can only be downloaded by logged in users

This section can only be seen by users with a valid subscription.
If you have a valid subscription, please login now

Your time
Stack Ideas HQ
Support is
Online

The support team is online and will be able to answer your inquiries. Please stay calm, follow the rules and do not cross post.

We will attend to you as soon as we can.