- Posts: 28
- Thank you received: 0
Suspicious files reported in security scan
- Karen
- Topic Author
- Offline
- Junior Member
-
Less
More
9 years 2 months ago #76145
by Karen
Suspicious files reported in security scan was created by Karen
Hello,
The following showed up in a recent audit of my website and I want to make sure that there is nothing wrong. Please review the following. Thank you.
Karen
/components/com_osmembership/tcpdf/CHANGELOG.TXT
suspicious lines to review:
PHARMA2T : PHARMACODE TWO-TRACKS
PHARMA : PHARMACODE
/components/com_osmembership/tcpdf/README.TXT
suspicious line to review:
* 1D and 2D barcodes: CODE 39, ANSI MH10.8M-1983, USD-3, 3 of 9, CODE 93, USS-93, Standard 2 of 5, Interleaved 2 of 5, CODE 128 A/B/C, 2 and 5 Digits UPC-Based Extension, EAN 8, EAN 13, UPC-A, UPC-E, MSI, POSTNET, PLANET, RMS4CC (Royal Mail 4-state Customer Code), CBC (Customer Bar Code), KIX (Klant index - Customer index), Intelligent Mail Barcode, Onecode, USPS-B-3200, CODABAR, CODE 11, PHARMACODE, PHARMACODE TWO-TRACKS, Datamatrix, QR-Code, PDF417;
The following showed up in a recent audit of my website and I want to make sure that there is nothing wrong. Please review the following. Thank you.
Karen
/components/com_osmembership/tcpdf/CHANGELOG.TXT
suspicious lines to review:
PHARMA2T : PHARMACODE TWO-TRACKS
PHARMA : PHARMACODE
/components/com_osmembership/tcpdf/README.TXT
suspicious line to review:
* 1D and 2D barcodes: CODE 39, ANSI MH10.8M-1983, USD-3, 3 of 9, CODE 93, USS-93, Standard 2 of 5, Interleaved 2 of 5, CODE 128 A/B/C, 2 and 5 Digits UPC-Based Extension, EAN 8, EAN 13, UPC-A, UPC-E, MSI, POSTNET, PLANET, RMS4CC (Royal Mail 4-state Customer Code), CBC (Customer Bar Code), KIX (Klant index - Customer index), Intelligent Mail Barcode, Onecode, USPS-B-3200, CODABAR, CODE 11, PHARMACODE, PHARMACODE TWO-TRACKS, Datamatrix, QR-Code, PDF417;
Please Log in or Create an account to join the conversation.
- Elliot Block
- Offline
- Senior Member
-
Less
More
- Posts: 73
- Thank you received: 2
9 years 2 months ago #76157
by Elliot Block
Replied by Elliot Block on topic Suspicious files reported in security scan
Hi Karen,
I'm not on Tuan's development team, but those are just text files that are included in the distribution of TCPDF which Membership Pro uses to dynamically produce the PDFs for subscribers (like receipts, invoices, etc.). Those files describe what the TCPDF developers changed over time and also describe how to use the package (the readme file). You or your clients have nothing to worry about.
Sidenote: Those change notes and readme entries correspond to the ability to include barcodes on the PDF.
Best,
Elliot
I'm not on Tuan's development team, but those are just text files that are included in the distribution of TCPDF which Membership Pro uses to dynamically produce the PDFs for subscribers (like receipts, invoices, etc.). Those files describe what the TCPDF developers changed over time and also describe how to use the package (the readme file). You or your clients have nothing to worry about.
Sidenote: Those change notes and readme entries correspond to the ability to include barcodes on the PDF.
Best,
Elliot
Please Log in or Create an account to join the conversation.
- Tuan Pham Ngoc
- Away
- Administrator
-
9 years 2 months ago #76256
by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Suspicious files reported in security scan
Hi Karen
That's part of TCPDF Library ( www.tcpdf.org/ ), a popular TCPDF library which we are using to generate invoice PDF in our extensions, so you don't have to worry about it
There are no security issues with it at all (at least until now)
Regards,
Tuan
That's part of TCPDF Library ( www.tcpdf.org/ ), a popular TCPDF library which we are using to generate invoice PDF in our extensions, so you don't have to worry about it
There are no security issues with it at all (at least until now)
Regards,
Tuan
Please Log in or Create an account to join the conversation.
Support
Documentation
Information
Copyright © 2025 Joomla Extensions by Joomdonation. All Rights Reserved.
joomdonation.com is not affiliated with or endorsed by the Joomla! Project or Open Source Matters.
The Joomla! name and logo is used under a limited license granted by Open Source Matters the trademark holder in the United States and other countries.
The Joomla! name and logo is used under a limited license granted by Open Source Matters the trademark holder in the United States and other countries.