Question: Security Vulnerability from Envato

Security Vulnerability from Envato

Hi, I received an email that there is a security vulnerability in SMA, and it was fixed in v3.4.35. What is it? I did some customisation already, so can't update directly. Which files will

NR

Nithin Reddy

Asked
Hi,

I received an email that there is a security vulnerability in SMA, and it was fixed in v3.4.35. What is it? I did some customisation already, so can't update directly. Which files will have the fix to it? I don't want people to hack the system. Please let me know!!
  • MS

    Mian Saleem

    Answered
    Hello,

    Envato found that installer is vulnerable to `xss attack` Installer is meant to be used by the purchaser only so we didn't care it. But as market team cares about this so we had no choice except to update the installer.

    We release update time to time with fixes to reported issues and bugs. There is no way for us to list the changes files but only the things fixed will be updated in the change log. Once modified, there is no way to update. We can't offer support for modification and modified versions :( Unfortunately this is quite bad situation but we don't have any alternative as the modification are done on base code.

    Thank you
  • MK

    Marwan Khanfar

    Answered
    How do we update existing installation?
  • MS

    Mian Saleem

    Answered
    **[Marwan Khanfar](/u/marwan)** Please download the latest file and follow the update instructions from the documentation.pdf Thank you
  • BS

    Barnamij Solution

    Answered
    Not Found
    The requested URL was not found on this server.

    Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.

    i am trying to install latest version but I m getting error after installation screen
  • BS

    Barnamij Solution

    Answered
    http://prnt.sc/t3u6wf
    http://prnt.sc/t3u75u
  • MS

    Mian Saleem

    Answered
    **[Barnamij Solution](/u/barnamij.solution)** Hello,

    Please check the 404 not found FAQ in the documentation.pdf

    If you still have issue then please ask new question with details and screenshots of the uploaded files.

    Thank you
  • AA

    Ammar Alkraidi

    Answered
    if you know the files you have customized, download a copy of the customized files on your machine. Download the update from your Envato account. Compare the customized files line by line with the update files. I normally use notpad++ with Compare plugin. it will set the your files side by side and highlights the lines with differences in both files. Then copy your customized lines to the update files. Just make sure there is no functionality conflict. Make sure to make a backup just in case things went south.
  • Login to Reply