Repository navigation
More information about the upgrade process can be found here.
This is a security patch for v36.0.0. Upgrading is recommended for all installations.
🔐 Security Fixes
- Stored XSS in the editor checklist block — checklist content was rendered as HTML, so stored markup could execute in another user's session. It is now handled as plain text in the browser and sanitised server-side before being persisted, and the save endpoint enforces manager/direct-report scoping. (#380)
- Unauthenticated include in
update.php— the endpoint could be reached without a session. It now requires an authenticated Admin and validates the requested module against an allowlist. (#381)
📄 Other
- Added
SECURITY.mdwith supported versions and the vulnerability reporting process (team@icehrm.com).