Jump to content
X2Community Forums

X2CRM Security Fixes


Recommended Posts

It has been brought to our attention that three vulnerabilities were found in our app. Please take the chance to look over the following fixes for these vulnerabilities and apply them to your installations. These fixes will also be included in our next version. 

 

Fixes: 

  1. Exception handling for invalid input to prevent SQL injection from the ActionHistoryChartWidget
  2. Permission check for Arbitrary file download via the global export in the admin control panel and when exporting themes
  3. Field purification when processing requests to prevent cross-site scripting (XSS)

Files:

Pull Request:

https://github.com/X2Engine/X2CRM/pull/160

 

Make sure to take backups before applying any of these changes of course!

 

 

 

Thank you to SYSDREAM for bringing these vulnerabilities to our attention

  • Like 3
Link to post
Share on other sites
×
×
  • Create New...