VirtueMart 3.8.6 comes to address a new Cross-site Scripting (XSS) security vulnerability caused by the manufactuer dropdown which was found by 4N_CURZE.

The problem itself was easy to fix, although the value was whitelisted everywhere else, it was missing for the manufacturer drop-down list.

Besides, VirtueMart 3.8.6 also was added some new interesting features which are useful for real marketplaces, which offer products of different vendors. Multicart can be mentioned here. Multicart means for a multi-vendor shop, that there is an extra cart for each vendor. So when a customer buys products from different vendors he needs to do a checkout for every vendor.

Another new feature is payment/shipment restrictions by coupons. It can be used to offer customers other payment methods over the phone or for marketing campaigns like "use this coupon to get free shipment".

VirtueMart 3.8.6 introduced a required characters check, the toggleCartButton.js with MIT license. Then the textinput plugin can now be used for mandatory text. The VirtueMart recaptcha system also was improved to work according to the new Joomla standards and any Joomla captcha plugin.


DOWNLOAD VM3 NOW
VirtueMart 3 component (core and AIO)

New Features, Improvements for Multivendor

Extended Features

Language

Security

Payments

Development

Fixes

Thanks for reading!

» Browse for all VirtueMart Templates

» Browse for all VirtueMart Extensions