Elgg 1.8.17 and 1.7.20 have been released to address a few critical security issues. Be sure to upgrade immediately to protect your sites.
Thanks to Mike Kasper and an anonymous contributor for reporting these vulnerabilities to us privately via security@elgg.org.
1.8.17 also includes tons of other fixes:
Thanks to all contributors who worked on these releases:
If you would like to contribute to an Elgg release, fork our repository at GitHub.
info@elgg.org
Security issues should be reported to security@elgg.org!
©2014 the Elgg Foundation
Elgg is a registered trademark of Thematic Networks.
Cover image by Raül Utrera is used under Creative Commons license.
Icons by Flaticon and FontAwesome.
@michele
This means that changes have been made to one file. The changes include: two rows of code have been removed and two new rows have been added. (The removed rows have a red background color, and the added rows have a green background.)
@Michele View whole file's code also
its still not working for me... i ve clearly edited the file as in github
@Satheesh PM Maybe, 3rd plugins? Search overridings of this function: notify_user