Simple Machines is happy to release a new update to Simple Machines Forum 1.0 and 1.1. This release addresses a cross-site scripting vulnerability in the search function. Also a few smaller issues have been addressed.
Note that the fix for the SMF 1.0.x branch will be released as new version 1.0.9, while the fix for the 1.1 RC3 branch will merely be released as patched version, the version of the forum will remain 1.1 RC3 (therefore, most of the modifications should remain compatible).
If you currently have installed 1.0.8 or 1.1 RC3, you can do either of the following to upgrade:
* Use the package manager in your administration center - one click, and you're done.
* Download the update archive file from the download page, and upload all of the files from it.
* Download the modification file, attached to this message, and modify the files manually according to it.