Skip to content

2.8.9

@sergei-maertens sergei-maertens tagged this 24 Apr 08:08
On request the low severity security patches from 3.1.0 are backported.

* Administrators are no-longer able to change the submission summary PDF through the
  admin interface.
* SVGs uploaded through the admin interface, used for logos and favicons, are now
  automatically sanitized.
* The form preview seen by form designers in the admin now applies extra HTML sanitation
  on the client side. The backend already properly escaped this and the public UI was
  never affected.
Assets 2
Loading