Cross-site scripting vulnerability in admin-ajax.js

Posted in: Newspaper
Post count: 8

Hi,

We’ve received reports of a XSS (cross-site scripting) vulnerability in our installation of Newspaper from last year. It involves admin-ajax.js; probably safer not to give the details here in cased used maliciously.

How can I give the developers additional information and determine whether this has been fixed in the latest version?

Thanks,
Russell

Post count: 35449

Hi,

Indeed there was some problem in privies version of Newspaper, in the last theme version these problems are fixed, please update the theme -> https://tagdiv.com/update-newspaper-theme/

Thank you for your understanding!

Post count: 30

what files specifically address the exploits, without having to update to 9.7? Because of the way that 9.7 is structured it nukes all of the customizations that are in my child theme.

https://forum.tagdiv.com/topic/child-theme-and-9-7/

also, in the last version of 9.6.1 there is a directory labeled patch_9.6_9.6.1. what are those for and do those need to be uploaded separately to overwrite what is already in the existing Newspaper directory?

  • This reply was modified 7 years by pmats777.
Post count: 8

@Calin we have determined the vulnerability is not fixed in 9.7. How can I report it to you outside of a public forum? Would you then be able to send us a patch?

Post count: 35449

Hi @rjmiddleton,

You can send us an email at contact@tagdiv.com and report the problem.

Thank you for your message!

Hi @pmats777,

That patch_9.6_9.6.1 is a patch that allow to make changes in our theme using code, usually this patch is used only by the advanced users that have good php coding skills.

Thank you for your understanding!

Post count: 8

@Calin thanks, I’ve sent the details to that email address. Can you reply with next steps?

Post count: 8

@Calin I reported the issue to that email address 3 days ago but have not received any reply. Can you ensure that the email is read and answered?

Post count: 35449

Hi,

We receive your email and a developer will check if there is still a vulnerability and will reply back to you on email.

Thank you for your understanding!

Post count: 17

I think tagdiv should release patch for Newspaper 9.6.1 users. Because a lot of users, include me, use old version 9.6.1 because in 9.7.* cannot save current customization from child theme.

Post count: 35449

Hi,

Please check this topic -> https://forum.tagdiv.com/topic/important-new-update-newspaper-9-7/

Thank you!

Viewing 10 posts - 1 through 10 (of 10 total)
The forum ‘Newspaper’ is closed to new topics and replies.