5.2.3
| Security |
Fixed cross-site scripting vectors caused by improper input processing in module chrome layouts (CVE-2024-40747).
|
| Security |
Fixed an XSS vulnerability in the id attribute of menu lists caused by missing output escaping (CVE-2024-40748).
|
| Security |
Fixed an ACL access-control issue that allowed access to protected Joomla component views (CVE-2024-40749).
|
| Fixed |
Fixed button validation in the joomlaExtButtons TinyMCE plugin (#44507).
|
| Fixed |
Fixed validation of email addresses containing an apostrophe (#44527).
|
| Fixed |
Fixed the assignment of AssetTitle and AssetParentId values (#42493).
|
| Fixed |
Removed empty images and anchors from the Articles News, Articles Category and Articles modules (#42493, #44478, #44475).
|
| Fixed |
Removed an incorrect CSS class from the cancel link on the frontend verification-code page (#44473).
|
| Fixed |
Added multi-select support for checkbox fields (#44500).
|
| Fixed |
Fixed Smart Search suggestions when using a PostgreSQL database (#44384).
|
| Fixed |
Added an AllowDynamicProperties extension check to the pre-update checker (#44307).
|
| Fixed |
Fixed the handling of a nullable parameter in PHPCS (#44543).
|
| Fixed |
Fixed an extra closing curly brace in inline styles (#44532).
|
| Fixed |
Fixed a JavaScript error occurring when the toggleButton element is unavailable (#44555).
|
| Fixed |
Fixed case-insensitive plugin searches for languages using Unicode characters (#44525).
|
| Fixed |
Fixed a deprecation warning caused by incrementing a non-alphanumeric string (#44173).
|
| Fixed |
Prevented a newly assigned user password-reset requirement from being incorrectly cleared (#44519).
|
| Fixed |
Fixed incorrect button text generated by the back() method in CoreButtonsTrait (#44509).
|
| Fixed |
Updated the Tags Router to correctly detect pages that should return a 404 error (#44540).
|
| Fixed |
Added exception handling when retrieving a user in the Action Log model (#44358).
|
| Fixed |
Fixed the return type declaration in the IdentityAware trait (#44567).
|
| Fixed |
Updated the joomla/application library to version 3.0.3 to fix PHP deprecation warnings in the Web Client (#44585).
|
| Fixed |
Allowed multi-factor authentication to be completed before a required password reset (#44521).
|
| Fixed |
Fixed duplicate Action Log entries after a Joomla update (#44629).
|
| Fixed |
Fixed the “Invalid Response” error in the CLI extension:remove command when using the -n option (#44546).
|
| Fixed |
Fixed multi-factor authentication handling when a privacy consent is invalid (#44522).
|
| Fixed |
Added changelog URL refreshing when rebuilding the extension manifest cache (#44565).
|