Security release
This version of ContactUs addresses a number of security issues and further hardens the extension against issues which could have security impact under the right conditions.
To the best of our knowledge, nobody has previously used, discovered, or reported the security issues addressed in this release. As a result, we have no reason to believe they have been or are being actively exploited.
What's new
PHP and Joomla version compatibility is now enforced.
Previously, the supported PHP and Joomla version range was only checked when you installed or updated the component. If your host later changed your PHP version, or your site's Joomla version moved outside the range we tested against, the software kept running anyway. From this release, the supported range is checked and enforced every time the component runs, not only at install time. If your server's PHP version, or your site's Joomla version, falls outside what this release supports, the component's backend will show a clear message telling you exactly what to upgrade (or downgrade). To restore normal operation, either change your PHP/Joomla version to match a supported range, or install a version of Akeeba ContactUs that supports what you currently have.
Removed legacy error handler.
We removed our legacy custom error handler. If you are met with an Exception or PHP error when using our software, please go to your site's administrator, System, Global Configuration, and set Debug Mode to Yes and Error Reporting to Developer. Then, reproduce the error. You will get the same level of information as our now-removed error handler. It is enough to help us help you.
Bug fixes and security improvements
- [CRITICAL] Guests could read any stored contact message.
- [HIGH] Guests could overwrite any stored contact message.
- [MEDIUM] The layout URL parameter could make a page include a PHP file from outside the templates folder.
- [MEDIUM] Akismet API key was disclosed to visitors when Akismet is unreachable.
- [MEDIUM] Refused contact form submissions resulted in an HTTP 404 error page.
- [LOW] The version compatibility error disclosed exact PHP and Joomla versions on public pages.
- [LOW] Backend edit forms were readable by users without edit permissions.
- [LOW] Malformed array filter parameters caused persistent errors in backend list views.
- [LOW] Raw database or mailer error messages could be shown to visitors on oversized or invalid input.
- [LOW] The privacy policy URL was printed unescaped into the public form.
- [LOW] PHP warnings were logged on ordinary requests with missing consent or frontend errors.
Changelog
Critical bugs and important changes
- Guests could read any stored contact message
- PHP and Joomla minimum and maximum version compatibility is now enforced
Removed features
- Removed legacy error handler
Bug fixes
- When cleaning one cache failed, the remaining caches were not cleaned either
- [HIGH] Guests could overwrite any stored contact message
- [LOW] Backend edit forms were readable with inadequate permissions
- [LOW] Malformed array filter parameters caused persistent HTTP 500 errors in backend lists
- [LOW] PHP warnings were logged on ordinary requests with missing consent or frontend errors
- [LOW] Raw database or mailer error messages could be shown to visitors on oversized or invalid input
- [LOW] The privacy policy URL was printed unescaped into the public form
- [LOW] The version compatibility error disclosed exact PHP and Joomla versions on public pages
- [MEDIUM] Akismet API key was disclosed to visitors when Akismet is unreachable
- [MEDIUM] Refused contact form submissions resulted in an HTTP 404 error page
- [MEDIUM] The layout URL parameter could make a page include a PHP file from outside the templates folder
Miscellaneous changes
- Cache cleaning now targets the single cache folder that every Joomla 4+ application shares
- Declare the core.options permission so it can be granted per user group
- Funnelled the createQuery()/getQuery(true) compatibility branch through a single Helper\DbQuery::create() call
- Supported Joomla versions: 5.4 to 6.2
- Supported PHP versions: 8.1 to 8.6