Security problem discovered

We've found a security problem that affects all versions of Psych Desktop. The problem involves the public/ directory, which was not protected by a .htaccess file, allowing an attacker to upload a PHP script and execute it. The file for beta3 has been patched to prevent this from happening, however, the new package still has to be copied to the mirrors, which will take a few minutes.

The fix does not require you to re-install anything, all you need to do is copy the '.htaccess' file from files/ to public/. All users of Psych Desktop are encouraged to fix this immediately.

We try our best to keep Psych Desktop as secure as possible, but sometimes things like this slip. We've notified everyone we could find who had a Psych Desktop installation about this issue, and they have hopefully fixed the problem.

Post new comment

The content of this field is kept private and will not be shown publicly.