This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 3d
Productivity & Wikis
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
cloud
cloudhosting
crm
crm-multi-tenant-saas
crm-platform
laravel
+10 more
laravel-application
laravel-crm
laravel-framework
laravel-package
opensource
opensource-crm
opensource-crm-framework
php
vue
vuejs
Affected surfaces
auth
rbac
rce_ssrf
breaking_upgrade
Summary
AI summaryFixed IDOR agent record access control and unrestricted file upload vulnerabilities.
Full changelog
- #2581 [enhancement] Fixed responsive UI issues when page is zoomed.
- #2579 [feature] Allow group selection for individual view permission users.
- #2575 [enhancement] Added previous month's sales update in Kanban view.
- #2573 [enhancement] Added dashboard support for multiple pipelines.
- #2572 [enhancement] Added filter by tag option in Contacts > Persons.
- #2549 [enhancement] Added support tab feature.
- #2548 [enhancement] Allow search by phone and email when creating a lead.
- #2544 [enhancement] Added validate skills.
- #2543 [enhancement] Added Agents Skills folder.
- #2546 [feature] Quick Attribute now available at lead form.
- #2545 [feature] Added agent skills functionality.
- #2590 [fixed] Fixed page does not refresh after creating a record via Quick Add.
- #2589 [fixed] Fixed Quick Add not working for users with group and individual permissions.
- #2582 [fixed] Fixed pipeline field visible on public webform.
- #2571 [fixed] Fixed issue with lead creation.
- #2570 [fixed] Fixed auto-fill lead email issue.
- #2567 [fixed] Fixed IDOR agent record access control vulnerability.
- #2563 [fixed] Fixed Kanban infinite scroll duplicates issue.
- #2583 [fixed] Fixed SQL injection in rotten lead filter.
- #2559 [fixed] Fixed agent record access control issue.
- #2556 [fixed] Fixed installation config save issue.
- #2550 [fixed] Fixed Kanban infinite scroll duplicates.
- #2542 [fixed] Fixed stored XSS vulnerability in notes field.
- #2541 [fixed] Fixed quote description truncation issue.
- #2539 [fixed] Fixed lost revenue arrow UI issue.
- #2538 [fixed] Fixed missing translations.
- #2501 [fixed] Fixed sales owner not saved in organization.
- #2500 [fixed] Fixed activities date filter range issue.
- #2479 [fixed] Fixed textarea field not rendered in WebForm.
- #2471 [fixed] Fixed missing translations for lead won/lost modal.
- #2420 [fixed] Added missing mega search translations for settings and configurations.
- #2533 [fixed] Fixed GUI installation issue.
- #2454 [fixed] Fixed quote description truncation.
- #2407 [fixed] Fixed missing translations.
- #2157 [fixed] Fixed auto-fill lead email when creating a lead.
- #2258 [fixed] Fixed issue with same-as-billing-address field.
- #2585 [security] Fixed unrestricted file upload vulnerability.
- #2419 [security] Fixed stored XSS vulnerability in notes field.
Security Fixes
- Fixed IDOR agent record access control vulnerability (CVE not provided)
- Fixed unrestricted file upload vulnerability (CVE not provided)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Krayin
CRM solution for SMEs and Enterprises for complete customer lifecycle management.
Related context
Related tools
Beta — feedback welcome: [email protected]