Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


WHMCS Weekly Security Updates? WHMCS Security Advisory TSR-2013-009
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

WHMCS Weekly Security Updates? WHMCS Security Advisory TSR-2013-009

MonsteRMonsteR Member
edited November 2013 in General

Does this mean they fixed all the issues or just another weekly patch with their unsecure system?

http://blog.whmcs.com/?t=81890

Not sure about you guys but feeling if they can't sort their system out going to start looking or finding a developer or to code a new billing system.

«1

Comments

  • leapswitchleapswitch Patron Provider, Veteran

    It brings new issues like -
    1. Invalid token in tickets
    2. Ticket response popup
    3. Default symbol issue

    I am awaiting 5.2.15 now.

  • @leapswitch said:
    It brings new issues like -
    1. Invalid token in tickets
    2. Ticket response popup
    3. Default symbol issue

    I am awaiting 5.2.15 now.

    So all in all another unless patch?

  • leapswitchleapswitch Patron Provider, Veteran

    @MonsteR said:
    So all in all another unless patch?

    Yes. All our INR clients are getting $ invoices of same amount. For example Rs 600 domain renewal is now $600 !

  • There was a patch for the currency mismatch issue, download it from the whmcs forums.

  • cfgguycfgguy Member, Host Rep

    A million dollar company never walks alone! When you buy a product and accept their terms and conditions. You not just buying the features, you buying the bugs as well.

    And these guys are more concerned about their stuff. You have bought the ticket, now enjoy the show. :)

  • @MonsteR said:
    Not sure about you guys but feeling if they can't sort their system out going to start looking or finding a developer or to code a new billing system.

    I really didn't like blesta at first but I'm getting used to it, it is a a decent system though and it is 99.1% open source, so there is that...

  • leapswitchleapswitch Patron Provider, Veteran

    @rds100 said:
    There was a patch for the currency mismatch issue, download it from the whmcs forums.

    Thanks!

  • DewlanceVPSDewlanceVPS Member, Patron Provider

    Patch of patch coming soon... (Note: 2 bugs/security was found by Blesta and not by WHMCS self code audit team)

  • DewlanceVPSDewlanceVPS Member, Patron Provider
    edited November 2013

    @leapswitch said:

    1 INR bug/issue was founded by me but whmcs never fix this ;/

    http://www.webhostingtalk.com/showthread.php?t=1255873
    (I was post this 7 month ago and still this is not fixed)

  • @cfgguy said:
    A million dollar company never walks alone! When you buy a product and accept their terms and conditions. You not just buying the features, you buying the bugs as well.

    And these guys are more concerned about their stuff. You have bought the ticket, now enjoy the show. :)

    The only problem is: they stopped caring about the quality of their product long ago, regardless of making buckets full of money.

  • MonsteRMonsteR Member
    edited November 2013

    @javaj Looked at it not sure though would need to try it out somewhen

  • @Frost said:
    The only problem is: they stopped caring about the quality of their product long ago, regardless of making buckets full of money.

    Starting to seem like they don't care to much, As they can take the money profit more then enough to actually hire a security consultant or a code audit but if they have this hasn't made a difference.

  • Can someone explain the difference between 5.2.13 and 5.2.14?

  • Oxide said: Can someone explain the difference between 5.2.13 and 5.2.14?

    It is simple. 5.2.13 exists and 5.2.14 doesn't exist.

  • This is another stupid attempt by whmcs :X After upgrade so many issues. Funny! Even I need to pay another 49$ for annual update package now!

  • prometeusprometeus Member, Host Rep

    @rds100 said:
    It is simple. 5.2.13 exists and 5.2.14 doesn't exist.

    so we can be sure this can't break anything :-P

  • @prometeus i'm sure it'll break a lot of things too when they decide to release 5.2.14 :)

  • I find it funny how people are moaning over having to pay $49 for updates which will potentially keep there system safe in the long run with the security patches inside.

  • @INIZ said:
    I find it funny how people are moaning over having to pay $49 for updates which will potentially keep there system safe in the long run with the security patches inside.

    "The software update service allows customers access to the latest versions of WHMCS. The service does not imply continued development, maintenance, or critical fixes for any given version of WHMCS."

    You should see your ass back before commenting others.

  • @INIZ said:
    I find it funny how people are moaning over having to pay $49 for updates which will potentially keep there system safe in the long run with the security patches inside.

    If you looking to keep your system safe stay away from whmcs, Although they release patches it doesn't make a difference when there are as many security flaws arise with their code every week or so most of which isn't even reported.

  • PatrickPatrick Member
    edited November 2013

    @MonsteR said:
    If you looking to keep your system safe stay away from whmcs, Although they release patches it doesn't make a difference when there are as many security flaws arise with their code every week or so most of which isn't even reported.

    Not every week is it really though, this update was partly from the security audit they said they are performing and was an expected update sooner or later.

    @CentrioHost said:
    You should see your ass back before commenting others.

    And if you look at the release log you will see important/security updates in there, but I don't think I should be spending time arguing with someone who has no credibility whatsoever.

  • AlexanderMAlexanderM Member, Top Host, Host Rep

    bug in latest (.13) update. Client can submit a ticket, gets email, admin can see ticket, ticket is under "View ticket" but when they click the ticket URL They get "Ticket not found error"

  • @ehostlab "NAGIB MAHFUZ PLABON" Khankir pola "01843898230" valo hoe ja. Arsehole. Where you find scam! Funny jerk.

  • smansman Member
    edited November 2013

    @AlexanderM said:
    bug in latest (.13) update. Client can submit a ticket, gets email, admin can see ticket, ticket is under "View ticket" but when they click the ticket URL They get "Ticket not found error"

    I haven't seen that. At least not yet. I think I've had everything happen ticket wise since the update. Existing tickets and new tickets.

  • AlexanderM said: bug in latest (.13) update. Client can submit a ticket, gets email, admin can see ticket, ticket is under "View ticket" but when they click the ticket URL They get "Ticket not found error"

    Can't confirm that too. Works here. Hmm?

  • Anyone having issues with the pre-defined replies button? The page is throwing a JS error, so its not working -.-

  • Jono20201 said: Anyone having issues with the pre-defined replies button? The page is throwing a JS error, so its not working -.-

    Have a look here.

  • Nick_ANick_A Member, Top Host, Host Rep

    @TekStorm_James said:
    Have a look here.

    Anyone else having trouble downloading that file? Getting a permission error.

  • qpsqps Member, Host Rep
    edited November 2013

    @Nick_A said:
    Anyone else having trouble downloading that file? Getting a permission error.

    +1

    Was able to finally get it after several tries.

Sign In or Register to comment.