HomeSecurityCross-site scripting vulnerability in Tapatalk

Cross-site scripting vulnerability in Tapatalk

According to an email sent by the developers of the Tapatalk that comes in the form of a plug-in, a security flaw has been discovered.

tapatalk

The vulnerability allows third parties to perform cross-site scripting to change the content or behavior of the application in the user's web browser, without compromising the security of the underlying system.
The plug-ins that have been fixed concern the following systems:

vBulletin 3 v4.4.1
vBulletin 4 v5.0.1
phpBB 3 v4.4.1
IPB 3.4 v3.9.1
SMF 2 v3.9.5
Xenforo v2.0.4
MyBB v3.9.1
Kunena3 v1.1.5
Vanilla v1.4.2
WBB4 V1.0.1

If your forum platform is not included in the above list, it is not vulnerable to cross site scripting.
If you have any questions, you can contact the plugin development team directly at: support [at] tapatalk.com

Here is the warning email:

Dear Tapatalk Partner,

This message is to notify you of a security vulnerability that was found earlier this year in the Tapatalk plug-in. The issue involves a cross-site scripting vulnerability that may allow a third party to manipulate the content or behavior of a web application in a user's browser, without compromising the underlying system.

While our engineering team and other security apps have classified this as a low risk item and have not received any reports of compromised systems, we still recommend that you update your forum's Tapatalk plugin to the latest version available on our website.

Plug-ins versions that have been patched:

vBulletin 3 v4.4.1
vBulletin 4 v5.0.1
phpBB 3 v4.4.1
IPB 3.4 v3.9.1
SMF 2 v3.9.5
Xenforo v2.0.4
MyBB v3.9.1
Kunena3 v1.1.5
Vanilla v1.4.2
WBB4 V1.0.1

If your forum platform is not listed above, it is not vulnerable to the cross site scripting issue.
If you have any questions, please reply to this message and let us know. We will only be communicating this issue via email to avoid broadcasting the existence of the vulnerability and putting forum owners who have not yet updated in unnecessary risk.

 

Source: secnews.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS