NEOCROME
Seditio is a modular website engine :
  • Fully skinnable, XHTML 1.1 compliant
  • Pluggable, scalable, fast and stable.
  • Advanced built-in message boards.
  • Powered by PHP and MySQL.

Seditio v126 released (security related)

Posted on 22-01-2010 by Olivier C.

Whereas the normal next build for Seditio is 130, this build 126 is out to fix a missing security check when editing a page, someone could manage to impersonate an administrator and change the title, body or other fields for a page.

If you're running Seditio 125, it's highly recommended that you download this 126 package, and replace the file : system/core/page/page.edit.inc.php (that's the only difference between 125 and 126).

This patch is only critical for some configurations, anyway it IS recommended for all.

Download Seditio build 126 here !

Also, the version 130 should be out soon, and it will feature a self-updater to make life easier, so it's a good idea to upgrade to 126 right now, because 130 won't be able to self-update from versions older than 125.