MODX Revolution 2.5.7 Released

MODX Revolution 2.5.7 Released

This release of MODX Revolution fixes low-risk security issues that were found. It also corrects the inability to click on results in the manager search bar in both Chrome and Firefox.

Here are some of the highlights of 2.5.7:

  • Fix search bar results not clickable in Chrome & Firefox [#13405]
  • Improve transport package downloads to be more reliable and use additional methods to download. [#13419]
  • Make Forgot Password feature more secure [#13408]
  • Proper use of json_encode and error handling for outputArray() in processors [#13389]
  • Closing various low-risk security vectors for file inclusion, cross-site scripting (XSS) and more

 

The Importance of Being Current

The most effective way to ensure the safety of your MODX site and it's data is to always be running the latest version of the MODX software. MODX continues to grow in popularity and profile which only makes it a more prominent target for attack.

MODX will typically release security patch releases within days of a report of a critical vulnerability. Once they release a patch, you should make sure it gets applied to your MODX website. Recovery from site compromise is often very time consuming and can be catastrophic or very expensive.

What version is my site running?

Your current version can be found once logged into the manager along the top, in the right-hand corner. Please reference our blog post on How to find out what version of MODX you have for more help.

How do I get my website upgraded?

We have already scheduled upgrades for any customer with an existing maintenance agreement. So if you have a maintenance agreement with us you are good to go and no need to worry!

If you do not have a maintenance agreement with us not a problem. We offer updates to those who are not under a maintenance agreement for $180. Our updating involves a full backup of the database and files and thorough checking to make sure the upgrades were installed properly. If major issues do occur during the upgrade, we can roll back to how it was before we started or fully work through the issues after discussing costs and options with you.

To schedule the upgrade, please contact us at support@threeeyedbird.com and the team will get you started! For those who may want to attempt it yourself, details on how to do the upgrade can be found in the MODX documentation.