<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Phorum 5.2.20 released - Minor Security Fixes</title>
        <description> We are happy to announce our latest stable release Phorum-5.2.20.
It is a bug fix release over 5.2.19 fixing some issues reported (including patches, thanks folks!) and other collected changes since the last release.
Also includes some minor security fixes as can be seen below.

You can download this new release from our downloads page or our github page.

- fixed message pruning with umlauts in forum name
- fixed possible stored and reflected XSS on attachment preview (minor, only could affect the author himself)
- fixed minor security flaw on IIS and open redirect, reported by Curesec
- send 500 HTTP status code in case of database error
- Fix access check for user given only by user_id (fixing #892 )
- Fixed PHP 5.4 notice for iScramble code</description>
        <link>https://www.phorum.org/support/read.php?64,155912,155912#msg-155912</link>
        <lastBuildDate>Sat, 08 Aug 2026 22:44:22 -0500</lastBuildDate>
        <generator>Phorum 6.0.4</generator>
        <item>
            <guid>https://www.phorum.org/support/read.php?64,155912,156671#msg-156671</guid>
            <title>Re: Phorum 5.2.20 released - Minor Security Fixes</title>
            <link>https://www.phorum.org/support/read.php?64,155912,156671#msg-156671</link>
            <description><![CDATA[ There is a link on the Home Page [<a href="http://www.phorum.org/downloads/phorum-5.2.20.tar.gz" target="_blank" >www.phorum.org</a>]]]></description>
            <dc:creator>Scott Finegan</dc:creator>
            <category>Announcements</category>
            <pubDate>Thu, 03 Mar 2016 14:45:10 -0600</pubDate>
        </item>
        <item>
            <guid>https://www.phorum.org/support/read.php?64,155912,156670#msg-156670</guid>
            <title>Re: Phorum 5.2.20 released - Minor Security Fixes</title>
            <link>https://www.phorum.org/support/read.php?64,155912,156670#msg-156670</link>
            <description><![CDATA[ Hello,<br />
<br />
Please, what&#039;s going on? Currently your download page does not offer any v.5.2.x version.<br />
As a cite from [<a href="http://www.phorum.org/downloads.php" target="_blank" >www.phorum.org</a>]<br />
<span style="color:#0000FF"><br />
Current Stable Version<br />
(released at Jan 01, 1970)<br />
</span><br />
Or am I to stupid to find the download link over there? Tried with several web browser. But currently (03.03.2016) latest link seems to be <br />
phorum-5.1.25.zip]]></description>
            <dc:creator>tecmade</dc:creator>
            <category>Announcements</category>
            <pubDate>Thu, 03 Mar 2016 12:02:19 -0600</pubDate>
        </item>
        <item>
            <guid>https://www.phorum.org/support/read.php?64,155912,156513#msg-156513</guid>
            <title>Re: Phorum 5.2.20 released - Minor Security Fixes</title>
            <link>https://www.phorum.org/support/read.php?64,155912,156513#msg-156513</link>
            <description><![CDATA[ We did not test with php7, so might work, might not work.]]></description>
            <dc:creator>Thomas Seifert</dc:creator>
            <category>Announcements</category>
            <pubDate>Thu, 04 Feb 2016 15:56:44 -0600</pubDate>
        </item>
        <item>
            <guid>https://www.phorum.org/support/read.php?64,155912,156512#msg-156512</guid>
            <title>Re: Phorum 5.2.20 released - Minor Security Fixes</title>
            <link>https://www.phorum.org/support/read.php?64,155912,156512#msg-156512</link>
            <description><![CDATA[ Hi Thomas,<br />
<br />
does this release run with PHP7? Currently I&#039;m using Phorum version 5.2.19 and PHP5.4. My Webhoster pushes hard to PHP7...]]></description>
            <dc:creator>AkaWebmaster</dc:creator>
            <category>Announcements</category>
            <pubDate>Thu, 04 Feb 2016 11:20:39 -0600</pubDate>
        </item>
        <item>
            <guid>https://www.phorum.org/support/read.php?64,155912,156105#msg-156105</guid>
            <title>Re: Phorum 5.2.20 released - Minor Security Fixes</title>
            <link>https://www.phorum.org/support/read.php?64,155912,156105#msg-156105</link>
            <description><![CDATA[ Hello Thomas,<br />
<br />
This is great news, it is good to see a new version of Phorum.<br />
<br />
Thanks to all contributors ;-)]]></description>
            <dc:creator>cactux</dc:creator>
            <category>Announcements</category>
            <pubDate>Fri, 18 Sep 2015 06:11:49 -0500</pubDate>
        </item>
        <item>
            <guid>https://www.phorum.org/support/read.php?64,155912,155920#msg-155920</guid>
            <title>Re: Phorum 5.2.20 released - Minor Security Fixes</title>
            <link>https://www.phorum.org/support/read.php?64,155912,155920#msg-155920</link>
            <description><![CDATA[ We have a full docs section about upgrading:<br />
[<a href="http://www.phorum.org/docs/html/admin/ch02.html" target="_blank" >www.phorum.org</a>]<br />
<br />
and yes, just overwriting the files with the newer ones, if you have good backups.]]></description>
            <dc:creator>Thomas Seifert</dc:creator>
            <category>Announcements</category>
            <pubDate>Mon, 27 Jul 2015 01:10:11 -0500</pubDate>
        </item>
        <item>
            <guid>https://www.phorum.org/support/read.php?64,155912,155919#msg-155919</guid>
            <title>Re: Phorum 5.2.20 released - Minor Security Fixes</title>
            <link>https://www.phorum.org/support/read.php?64,155912,155919#msg-155919</link>
            <description><![CDATA[ Just one question here because I ran into this news a few moments ago from my forums&#039; Admin CP.<br />
<br />
I know it&#039;s a given to make sure to back up the current system <i>and</i> my forums&#039; database before doing the upgrade procedure; however, what <i>is</i> the best procedure to do this upgrade itself to the new version? Is it simply just overwriting most of the files of the previous version with the new version that has just been posted?<br />
<br />
Once again, I am well aware of backing up the previous system&#039;s files <i>and</i> the database, considering that one of them contains the info needed to connect to the database on the server host I&#039;m using. All right; thanks again.]]></description>
            <dc:creator>mcfp_2013</dc:creator>
            <category>Announcements</category>
            <pubDate>Sun, 26 Jul 2015 20:15:05 -0500</pubDate>
        </item>
        <item>
            <guid>https://www.phorum.org/support/read.php?64,155912,155915#msg-155915</guid>
            <title>Re: Phorum 5.2.20 released - Minor Security Fixes</title>
            <link>https://www.phorum.org/support/read.php?64,155912,155915#msg-155915</link>
            <description><![CDATA[ 1. thats the automatically generated name by github, yeah everything can be done on your own but I decided to not for now.<br />
2. yes, no longer being generated. Changelog is given on the page at the downloads.<br />
3. yes, currently the docs are only generated on the website, no need to distribute it all the time.]]></description>
            <dc:creator>Thomas Seifert</dc:creator>
            <category>Announcements</category>
            <pubDate>Fri, 24 Jul 2015 15:01:47 -0500</pubDate>
        </item>
        <item>
            <guid>https://www.phorum.org/support/read.php?64,155912,155914#msg-155914</guid>
            <title>Re: Phorum 5.2.20 released - Minor Security Fixes</title>
            <link>https://www.phorum.org/support/read.php?64,155912,155914#msg-155914</link>
            <description><![CDATA[ Hi Thomas,<br />
<br />
I just started to upgrade to the new version.<br />
<br />
My first observations:<br />
<br />
<ul><li> The folder inside the ZIP-File is called Phorum-Core-68a6d88. I think this folder should be called phorum-5.2.20 instead. </li><li> File /docs/NEWS is missing. </li><li> The folder /docs/html/ and his subfolders seem incomplete. Compared to 5.2.19 a lot of files a missing. </li></ul>
<br />
Regards<br />
Oliver]]></description>
            <dc:creator>Oliver Riesen-Mallmann</dc:creator>
            <category>Announcements</category>
            <pubDate>Fri, 24 Jul 2015 07:12:25 -0500</pubDate>
        </item>
        <item>
            <guid>https://www.phorum.org/support/read.php?64,155912,155912#msg-155912</guid>
            <title>Phorum 5.2.20 released - Minor Security Fixes</title>
            <link>https://www.phorum.org/support/read.php?64,155912,155912#msg-155912</link>
            <description><![CDATA[ We are happy to announce our latest stable release Phorum-5.2.20.<br />
It is a bug fix release over 5.2.19 fixing some issues reported (including patches, thanks folks!) and other collected changes since the last release.<br />
Also includes some minor security fixes as can be seen below.<br />
<br />
You can download this new release from <a href="http://www.phorum.org/downloads.php" target="_blank" >our downloads page</a> or our github page.<br />
<br />
- fixed message pruning with umlauts in forum name<br />
- fixed possible stored and reflected XSS on attachment preview (minor, only could affect the author himself)<br />
- fixed minor security flaw on IIS and open redirect, reported by Curesec<br />
- send 500 HTTP status code in case of database error<br />
- Fix access check for user given only by user_id (fixing #892 )<br />
- Fixed PHP 5.4 notice for iScramble code]]></description>
            <dc:creator>Thomas Seifert</dc:creator>
            <category>Announcements</category>
            <pubDate>Sun, 19 Jul 2015 07:43:28 -0500</pubDate>
        </item>
    </channel>
</rss>
