2024R1.3.6
- November 13, 2025
Security
- Fixed a sudo vulnerability where the `www-data` user could execute commands as the `root` user (Thanks to Cory Billington for reporting this) [GL:NLS#719] – JM
- Wrapped several user-provided command arguments in escapeshellarg() to prevent shell injection (Thanks to Cory Billington for reporting this) [GL:NLS#720] – JM
Fixed
- Fixed duplicate error messages when entering an invalid key [GL:NLS#128] – JM
- Improved the alert creation error message regarding interval times [GL:NLS#129] – JM
