Security Advisory - Plugin vulnerabilities
Plugin XSS advisory: the System Overview and Feed Reader plugins in Blesta 3.0.0 through 3.0.4 render content unsanitized. Fixed in the 3.0.5 patch.
Blog · publishing since 2008
Release announcements, version previews, security advisories, and the occasional detour — written by the team building Blesta.
Plugin XSS advisory: the System Overview and Feed Reader plugins in Blesta 3.0.0 through 3.0.4 render content unsanitized. Fixed in the 3.0.5 patch.
Cross-site scripting advisory for Blesta 3.0.0 through 3.0.3: two message types render without sanitization. Both issues are fixed in the 3.0.4 patch.
ModulesGarden releases cPanel Extended for Blesta, letting clients manage FTP, email, databases, subdomains, addon domains, and cron jobs from the Blesta client area.
30-day free trial · No credit card · Your server
Everything on this blog ships in the box. Full product, free for 30 days, on your own server.