|
Dec 23rd |
Elgg 1.7.6 released with security enhancementsElgg 1.7.6 has been released with important security enhancements to address a possible SQL injection attack using crafted URLs. All 1.7 users should upgrade immediately to keep their networks and servers safe. Thanks to Gerrit Venema from Gol Gol social community for following the security reporting guidelines and working with us to get a fix out! In addition to security enhancements, Elgg 1.7.6 also contains a few bugfixes:
For developers, two API changes are included:
Please download 1.7.6 and upgrade your site immediately. As a reminder, all bug reports should be filed at trac and all security issues should be emailed to security [at] elgg [dot] org.
|