Joomla! 1.0.14 was released on February 11, 2008. It fixed several serious security vulnerabilities. These include
- SECURITY[LOW] Fixed XSS issue in Search Component.
- SECURITY[LOW] Fixed XSS issue in Search results pages.
- SECURITY[LOW] Disallowed users from adding extra wildcard filters in search strings.
- SECURITY[LOW] Fixed multiple typos in back end Content Component making array integer check ineffective.
- SECURITY[LOW] Fixed case-sensitive flaw in Input Filter.
- SECURITY[HIGH] Fixed CSRF issue allowing portal compromise - Administrator components.
- Administrator logout problem.
- Fixed bug in Search Component where small word were not properly filtered out.
- Improved efficiency of regular expressions in Search Component (thus reducing CPU resources when called).
- Added "Preview" link to Administrator template (to match 1.5).
- Fixed bug in pagination links (extra space was being added to the link).
- Various core API fixes.
0 comments: