Skip to content

v2.3.9 Patch #1

Choose a tag to compare

@dleffler dleffler released this 13 Sep 20:13
· 2764 commits to master since this release

v239patch1 adds these features to v239:

  • update rss/podcast feeds to include language and remove 'generator' comment since we include that element tag

v239patch1 fixes these issues in v239:

  • security fix (v2.3.0+) to prevent uploading files to wrong location, thanks to Balisong
  • security fix to prevent possible sql injections, thanks to Manuel Garcia Cardenas and PKAV TEAM
  • fix filedownload facebook meta tags to include link to audio/video reference if it is 1st attached file
  • fix events reminder email embedded links and update styles including using bootstrap2/3 if using that theme framework
  • fix possible facebook meta issues; sending wrong 'type'
  • fix bootstrap3 calendar views to not display date selector in printer friendly view
  • regression fix (v2.3.9) .htaccess is too restrictive for uploaded media files

v239patch1 updates these 3rd party libraries in v239:

  • TinyMce to v4.4.3
  • CKEditor to v4.5.11
  • bootstrap-dialog to v1.35.3
  • elfinder to v2.1.15
  • mediaelement.js to v2.23.0
  • bootstrap duallistbox to v3.0.6
  • bootstrap datetimepicker to v4.17.42
  • moment.js to v2.15.0 (needed by bootstrap datetimepicker)
  • yadcf to v0.9.0