This is an old revision of the document!
Release notes are cumulative for all builds of v2.5
VGO-2146 Addressed a vulnerability where an attacker might bypass authentication. VGO-2148 Address a vulnerability where information was disclosed in the form of API documentation VGO-2149 Addressed a vulnerability where access rights at the function level have been verified. VGO-2150 Addressed a vulnerability to remote code execution (RCE) VGO-2151 Addressed a vulnerability to SQL injection attacks originating from input verification. VGO-2152 Addressed CSRF vulnerability. VGO-2153 Addressed a vulnerability where the application allowed the upload of an SVG file containing HTML content. VGO-2154 Addressed a vulnerability where references to internal objects were not secure. VGO-2155 Addressed a vulnerability denominated Persistent XSS attack where an injected script is permanently stored on the target servers, such as in a database, in a message forum, visitor log, comment field, etc. VGO-2156 Addressed a vulnerability where some sensitive data was exposed to attack. VGO-2157 Addressed a vulnerability where attacks aim at discovering non-public web services by retrieving their WSDL files. VGO-2159 Addressed a vulnerability where by using old session cookies, user profiles can be accessed VGO-2176 HTTP is no longer permitted. HTTPS must be deployed with a valid certificate. VGO-2177 The session timeout setting for end-users and administrators have been merged. There is only one setting across the site. VGO-2182 Some ad blocker extensions to the browser may cause problems with the Admin Console. Please disable any extensions that block the Versago site VGO-2185 Addressed an issue where the password field for a new user was not large enough. Expanded to max 32 characters. See https://wiki.twbs.com/doku.php/versago/role_profile_user_configuration#user_details_- _core_information for more information. VGO-2192 Addressed a vulnerability where several HTTP methods designed to aid developers in deploying and testing applications were allowed. VGO-2195 Addressed a vulnerability where a Referrer-Policy was not being used. VGO-2196 Addressed a vulnerability where HTML comments were exposed. VGO-2220 Addressed an issue with reports that allow record submission where the field's length created to store the submission was limited to 50 characters VGO-2221 Addressed an issue where action links to an https site were not working properly VGO-2235 Mask passwords will no longer be displayed in pages where there is a password field such as DB connections and Email settings. If the password needs to be changed, the Update Password button must be clicked first in order to enable the field VGO-2240 Address an issue where action links did not export correctly. If a form contained multiple action links and it was imported and exported, all links would point to the same link in the new environment VGO-2247 Addresses an issue where images in Crystal Reports were not displayed VGO-2296 Addressed an issue where system session time out did not follow the set value