Joomla! 1.0.14 released

User Rating: / 0
PoorBest 
Wednesday, 13 February 2008 07:45

The Joomla! Community announced the release of Joomla! 1.0.14 [Daybreak]. This version fixes serious security vulnerabilitites that have been discovered since the release of Joomla! 1.0.13. 

Security fixes:

  • SECURITY [LOW]  Fixed XSS issue in Search Component.
  • SECURITY [LOW]  Fixed XSS issue in Search results pages.
  • SECURITY [LOW]  Disallowed users from adding extra wildcard filters in search strings.
  • SECURITY [LOW]  Fixed multiple typos in back end Content Component making array integer check ineffective.
  • SECURITY [LOW]  Fixed case-sensitive flaw in Input Filter.
  • SECURITY [HIGH]  Fixed CSRF issue allowing portal compromise - Administrator components.

Other Significant Fixes

  • Administrator logout problem.
  • Fixed bug in Search Component where small word were not properly filtered out.
  • Improved efficiency of regular expressions in Search Component (thus reducing CPU resources when called).
  • Added "Preview" link to Administrator template (to match 1.5).
  • Fixed bug in pagination links (extra space was being added to the link).
  • Various core API fixes.

Link | Release Notes - Download J! 1.0.14

Last Updated on Wednesday, 13 February 2008 07:46