2024R1.1.2

Security

  • Fixed an issue where unused API endpoints posed a security vulnerability (Thanks to Márk Rákóczi for reporting this) [GL:XI#1036] – DA

Fixed

  • Fixed an issue where any user could modify an insecure login ticket (Thanks to Márk Rákóczi for reporting this) [GL:XI#1037] – DA
  • Fixed an issue where the login form would submit to the current url and not login.php (Thanks to Kevin De Frene for reporting this) [GL:XI#1041] – DA