5.8.3
- March 31, 2021
Security
- Updated email validation to require RFC 822 valid email addresses to fix possible security vulnerabilities -JO
- Fixed XSS vulnerability in user Email Address field when on Send Test Notification page -JO
- Fixed possible RCE vulnerability via Email Address not being properly validated (CVE-2020-24899) -JO
Updated
- Updated jQuery to version 3.6.0 to fix minor issues -JO
Fixed
- Fixed install process on Oracle Linux 8 due to mod_php being used instead of php-fpm like CentOS/RHEL -JO
- Fixed config/ endpoints to properly display array of contacts (and other objects) when using append (+) in config [TPS#15509] -JO
- Fixed argument quoting in mysqlrepair and restore_xi scripts -DC,JO
- Fixed issue with Scheduled Backups sending local backup success email with SSH or FTP emails [TPS#15501] -JO
- Fixed API help/example PUT config calls not working properly due to space not being url encoded [TPS#15505] -JO
- Fixed scheduled reports jobs not changing with username change [TPS#15502] -JO
- Fixed issue where masquerade button in the Manage Users page wasn’t working on some OS/PHP versions -JO
- Fixed issues with MIB integration after upgrading to SNMPTT 1.4.2 [TPS#15376] -SAW
- Fixed issues with Undo Trap Processing button [TPS#15500] -SAW
- Fixed issue with downgraded ndo2db systems where limited users would not properly load data due to is_ndo_loaded failing -JO
