Over 1 million people have joined Mastodon since October 27. Between that and those who returned to their old accounts, the number of active users has risen to over 1.6 million today, which, for context, is over 3 times what it was just about two weeks ago!
๐จ๐จ New research alert! ๐จ๐จ
@cornerpirate shows how he was able to leverage a XSS vulnerability within Textpattern CMS to obtain Remote Code Execution (RCE) on the backend server.
Remember, if you are using Textpattern CMS v4.8.7, please update now. https://t.co/X95H5fcPdf
Team Textpattern gratefully appreciate the detailed report and research undertaken by @cornerpirate, the identification and resolution of this issue makes all Textpattern users safer. Thanks, Paul!
Textpattern 4.8.8 includes a fix for a security issue reported by @cornerpirate at @pentestltd. They have published an article with details. If you're running Textpattern 4.8.7 or earlier, we recommend updating to Textpattern 4.8.8 to resolve this.
https://t.co/FLuH2PNz64
@textpattern@pentestltd If a security researcher finds this, you know that Textpattern dealt with this professionally and efficiently. They have a disclosure process. I recommend reading what is excluded from the scope because there is an important acceptance of risk they are doing you should know.
Textpattern 4.8.8 is ready. Thank you for your patience.
There is a security fix included, thanks to a responsibly-disclosed report from @pentestltd. More on that to follow.
https://t.co/If2NpIBwdg
https://t.co/hZmebEfQGC
๐๐๐
If you are able to give 4.8.8 beta.1 some time, eyeballs and brain cycles, then report any problems to us, this will help us *massively* in making 4.8.8 as good as it can be.
We hope to see you again in around two weeks with a full release announcement.
Thank you. [2/2]
We released Textpattern 4.8.8 beta.1 on Jan 1st, 2022. It has support for PHP 8.1, optimisations and many small tweaks (improvements).
We hope to release 4.8.8 in the next two weeks.
We want to focus on Textpattern 4.9 and all the *new* and *extra* features it will bring. [1/2]