<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://3.19.219.109/index.php?action=history&amp;feed=atom&amp;title=Version_6.3.2_Release_Notes</id>
		<title>Version 6.3.2 Release Notes - Revision history</title>
		<link rel="self" type="application/atom+xml" href="http://3.19.219.109/index.php?action=history&amp;feed=atom&amp;title=Version_6.3.2_Release_Notes"/>
		<link rel="alternate" type="text/html" href="http://3.19.219.109/index.php?title=Version_6.3.2_Release_Notes&amp;action=history"/>
		<updated>2026-04-04T15:44:07Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.29.1</generator>

	<entry>
		<id>http://3.19.219.109/index.php?title=Version_6.3.2_Release_Notes&amp;diff=21622&amp;oldid=prev</id>
		<title>Matt at 18:36, 29 December 2016</title>
		<link rel="alternate" type="text/html" href="http://3.19.219.109/index.php?title=Version_6.3.2_Release_Notes&amp;diff=21622&amp;oldid=prev"/>
				<updated>2016-12-29T18:36:04Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 18:36, 29 December 2016&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l5&quot; &gt;Line 5:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 5:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Release Type: Security&amp;lt;br /&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Release Type: Security&amp;lt;br /&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Release Date: 29th December 2016&amp;lt;br /&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Release Date: 29th December 2016&amp;lt;br /&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Distribution Types: Full Version&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;, &lt;/del&gt;Incremental &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;and via Automatic Updater&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Distribution Types: Full Version &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;and &lt;/ins&gt;Incremental&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/div&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/div&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Matt</name></author>	</entry>

	<entry>
		<id>http://3.19.219.109/index.php?title=Version_6.3.2_Release_Notes&amp;diff=21618&amp;oldid=prev</id>
		<title>Matt: Created page with &quot;&lt;div class=&quot;docs-alert-info&quot; style=&quot;max-width:370px;&quot;&gt; &lt;span class=&quot;title&quot;&gt;Release Information&lt;/span&gt; &lt;br /&gt; Version: 6.3.2&lt;br /&gt; Release Type: Security&lt;br /&gt; Release Date: 29...&quot;</title>
		<link rel="alternate" type="text/html" href="http://3.19.219.109/index.php?title=Version_6.3.2_Release_Notes&amp;diff=21618&amp;oldid=prev"/>
				<updated>2016-12-29T18:35:47Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;&amp;lt;div class=&amp;quot;docs-alert-info&amp;quot; style=&amp;quot;max-width:370px;&amp;quot;&amp;gt; &amp;lt;span class=&amp;quot;title&amp;quot;&amp;gt;Release Information&amp;lt;/span&amp;gt; &amp;lt;br /&amp;gt; Version: 6.3.2&amp;lt;br /&amp;gt; Release Type: Security&amp;lt;br /&amp;gt; Release Date: 29...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;lt;div class=&amp;quot;docs-alert-info&amp;quot; style=&amp;quot;max-width:370px;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;span class=&amp;quot;title&amp;quot;&amp;gt;Release Information&amp;lt;/span&amp;gt;&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
Version: 6.3.2&amp;lt;br /&amp;gt;&lt;br /&gt;
Release Type: Security&amp;lt;br /&amp;gt;&lt;br /&gt;
Release Date: 29th December 2016&amp;lt;br /&amp;gt;&lt;br /&gt;
Distribution Types: Full Version, Incremental and via Automatic Updater&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Update/Download==&lt;br /&gt;
&lt;br /&gt;
A full download and incremental patch set version can be downloaded via the [http://download.whmcs.com/ Downloads page]. [[Upgrading|See Manual Upgrade Steps]]&lt;br /&gt;
&lt;br /&gt;
==Release Notes==&lt;br /&gt;
&lt;br /&gt;
===PHPMailer Security Advisory===&lt;br /&gt;
&lt;br /&gt;
 '''Exploit type:''' Remote Code Execution in third-party PHPMailer library&lt;br /&gt;
 '''CVE Numbers:''' CVE-2016-10033 and CVE-2016-10045&lt;br /&gt;
&lt;br /&gt;
====Description====&lt;br /&gt;
&lt;br /&gt;
All versions of the third-party PHPMailer library distributed with WHMCS are vulnerable to a remote code execution vulnerability. This is patched in PHPMailer 5.2.20.&lt;br /&gt;
&lt;br /&gt;
At this time we do not believe the deficiency in PHPMailer is exposed in WHMCS due to our own validation of user input.  Furthermore, the vulnerability requires being able to pass user input unfiltered to a message's &amp;quot;from&amp;quot; address, which in WHMCS is only defined within the admin configuration and only accessible to a trusted admin user.&lt;br /&gt;
&lt;br /&gt;
Irrespective of the known protections in the WHMCS product, this CVE represents a serious issue for PHPMailer. Therefore to mitigate any undiscovered risk or risk to 3rd party extensions using PHPMailer directly, we are releasing updates for all versions of WHMCS in active and long term support to provide the latest PHPMailer library version 5.2.21.&lt;br /&gt;
&lt;br /&gt;
The fix provided by PHPMailer in 5.2.20 for CVE-2016-10045 introduces stricter validation of the sender email address. In most cases, this will not present any problems. However, the fix does break RFC compliance for sender addresses and so more obscure email addresses while technically valid may be rejected by PHPMailer following this change.&lt;br /&gt;
&lt;br /&gt;
====Further Reading====&lt;br /&gt;
&lt;br /&gt;
# https://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10033-Vuln.html&lt;br /&gt;
# https://legalhackers.com/advisories/PHPMailer-Exploit-Remote-Code-Exec-CVE-2016-10045-Vuln-Patch-Bypass.html&lt;br /&gt;
# https://github.com/PHPMailer/PHPMailer/blob/master/SECURITY.md&lt;br /&gt;
# https://github.com/PHPMailer/PHPMailer/wiki/About-the-CVE-2016-10033-and-CVE-2016-10045-vulnerabilities&lt;br /&gt;
&lt;br /&gt;
==Template Changes==&lt;br /&gt;
&lt;br /&gt;
None&lt;br /&gt;
&lt;br /&gt;
==Changelog==&lt;br /&gt;
&lt;br /&gt;
===Version 6.3.2 ===&lt;br /&gt;
{{:Changelog:WHMCS V6.3.2}}&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Matt</name></author>	</entry>

	</feed>