Hi Micker,
Actually I had not seen that.. So a huge thank you. In the end I found it in another thread as well - in english
with the patch someone posted, and also found the info on the manual change.
Do you know if this patch is this included in 1.5.3? Looking at the dates, I don't think it is.
I am just a little worried.. although it is not 'technically' a problem with Flexicontent itself, one or two postings on the Joomla Security vulnerabilities list saying FlexiContent has problems, and it could spell big problems.
Personally, I have 3 sites down due to this vulnerability.. and it has cost me a lot of time to clean up, let along the loss of confidence by my clients in the FlexiContent.
I have read a few other posts with concerns about release / update schedules, and I have to agree.. things need to happen more regularly... at least announcing information like this.. I mean this is nessasary information for anyone running FC!
I understand that Emmanuel does this for free, and why things take time (and I think he does an amazing job), but if security problems show up, even just in included 3rd party 'parts' and the community is not informed, then the people will loose confidence in the product, and without the community using it, there wont be a FlexiContent ( and that would be terrible )
Can I suggest, on the FC homepage, that a BIG notice is placed about the problem and how to fix it. I have already had to move one client to K2 as the host will not allow me to reinstall FC!! (They're not a great host but the clients choice so nothing I can do) and I would hate for more people to have problems like this.
Anyway, mainly a big thank you for the link.. but thought I would share my thoughts.
Many thanks