Download phpBB 3.0.7-PL1

Spread the love

With phpBB it is possible to set up a forum where visitors can discuss with each other. The package is made available under the gpl license and uses PHP and a database to store messages, supporting PostgreSQL, Firebird, MSSQL and SQLite as databases in addition to the popular MySQL. Version 3.0.7-PL1 has been available for a few days and fixes a security problem. The announcement of this release is as follows:

phpBB 3.0.7-PL1 released

We are sorry to announce the immediate release of phpBB 3.0.7-PL1 to address a security issue which was introduced in 3.0.7, unfortunately the issue wasn’t noticed during testing and has only surfaced a week after the release of 3.0.7 .

We promised working feeds for phpBB 3.0.7. Sadly, we were not able to deliver on that promise – a critical bug in the permission handling for feeds slipped past. To all people who already have updated to 3.0.7, it is of critical importance to update to 3.0.7-PL1. Otherwise, it is possible for users to bypass permission settings under the following circumstances:

  • Feeds are enabled
  • Any of the posts or topics feeds are enabled
  • The unauthorized user – or one of the groups they are a member of – have forum permissions set on a private forum
  • If you have excluded a forum from the list of forums that provide feeds, it is unaffected

Note: We recommend the use of a regular update routine over manually editing your files. If you manually edit your files your board will not recognize the update.

There were no other changes, in particular neither style nor language changes.

Version number 3.0.7-PL1
Release status Final
Operating systems script language
Website phpBB
Download http://www.phpbb.com/downloads/
License type GPL
You might also like