A Security related bug has been found in the Website Baker CMS.
Affected systems * Only Website Baker version 2.8.0
* Only installations which have enabled the options to sign in or to change user settings in the frontend
Vulnerability Impact * Spamming, annoying and impersonating registered users
* To protect still unpatched systems, no further details will be published during the next 3 months
Maximum Severity Rating * High (for systems matching all of the conditions under the Affected Systems section)
* None (for all other systems)
Instructions how to patch- Just download the patched file attached to this message
- Unzip this file
- Replace the file /framework/class.wb.php with the patched version by ftp
AcknowledgementsWe want to thank the users Chio, Thorn and Stefek for reporting this bug in an appropriate manner.
Frank Heyne
(Website Baker Security Team)