Skip to content

UVDesk

v1.1.8 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

agent-privilege backbonejs customer-support docker-runtime ecommerce-apps ecommerce-apps-integration
+12 more
freshdesk-alternative knowledgebase mailboxes opensource osticket-alternative support-tickets symfony4 ticketing-system uvdesk uvdesk-community workflows zendesk-alternative

Summary

AI summary

Fixed Cross-Site Scripting (XSS) security issues and a vulnerability related to access privilege.

Full changelog

Release Notes v1.1.8

:sparkling_heart: Features

  • Added rating on ticket view provided by customer based on support provided.
  • Updated UI - Added plus icon for ticket create, agent create etc.
  • Updates for search by filter for ticket list, added drop-down to select and element before search
    (Id, email, subject).
  • User created notes with different colour on ticket view.
  • Added assigned agent access details on ticket view, admin can all the access provided to that agent.
  • Updated some icons on dashboard for Microsoft apps etc.
  • Display all shared saved replies to admin and super admin.
  • Use remote image display in emails by embedding images.
  • Added feature to send notification on webhook URL for ticket create and replies with all details.
  • Updated UI for the customer ticket creation and login forms.
  • Enhanced functionality and design of the marketing announcement section.
  • Added a Public Link URL feature for ticket access without customer login.
  • Added a setting to configure how much time a public link can be accessed.
  • Updated default theme colour and brand colours.
  • Updated svg for marketing announcement and other svg icons
  • Updated admin logo colour to match the dynamic banner background colour.
  • Added Portuguese translation language.
  • Dockerfile updates.

:mountain_bicyclist: Misc. Updates

  • Code Refactoring for all dependent packages.
  • Update related to remember cookies functionality.

:bug: Bug Fixes

Issues Fixed in Core Framework

  • Added conditional operator for getting email in case not getting email in mail parameter for Microsoft app.
  • Updated doctrine-migration package.
  • Fixed Cross-Site Scripting (XSS) security issues.
  • Fixed security issue related to access privilege.
  • Fixed vulnerabilities issue related to saved replies.

Issues Fixed in support-center-bundle

  • Issue fixed for large size attachment zip download.
  • Fixed vulnerability broken security issue.

Please refer to CHANGELOG-1.1.md for more information regarding updates included in this release.

Security Fixes

  • Fixed Cross-Site Scripting (XSS) security issues.
  • Fixed security issue related to access privilege.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track UVDesk

Get notified when new releases ship.

Sign up free

About UVDesk

UVDesk community is a service oriented, event driven extensible opensource helpdesk system that can be used by your organization to provide efficient support to your clients effortlessly whichever way you imagine.

All releases →

Related context

Beta — feedback welcome: [email protected]