| Security |
Fixed XSS vectors in the OutputFilter::strip* methods caused by improper input handling (CVE-2024-40743).
|
| Security |
Fixed improper ACL checks in the administrator profile view that allowed backend users to overwrite their usernames when this action was prohibited (CVE-2024-27187).
|
| Security |
Fixed XSS vulnerabilities in HTML mail templates caused by missing data escaping (CVE-2024-27186).
|
| Security |
Fixed cache-poisoning vectors caused by arbitrary parameters being included in pagination links (CVE-2024-27185).
|
| Security |
Improved internal URL validation to prevent redirects to external resources (CVE-2024-27184).
|
| Fixed |
Updated the TinyMCE editor to version 6.8.4 (#43808).
|
| Fixed |
Fixed attachment handling in the Mail class (#43828).
|
| Fixed |
Added removal of Schema.org data after the associated item is deleted (#43839).
|
| Fixed |
Removed the testing update channel from the command-line interface (#43764).
|
| Fixed |
Fixed frontend language handling on multilingual sites without the Backward Compatibility plugin enabled (#43791).
|
| Fixed |
Removed unused variables (#43763).
|
| Fixed |
Added the missing security token to the ModalSelect field (#43745).
|
| Fixed |
Fixed the Secure attribute for user session cookies (#43882).
|
| Fixed |
Fixed data encoding in popup links (#43874).
|
| Fixed |
Fixed header translation for modal selection fields (#43878).
|
| Fixed |
Fixed a JavaScript error affecting radio buttons rendered in a sublayout (#43804).
|
| Fixed |
Fixed the handling of relative URLs in private messages (#43897).
|