This is an old revision of the document!
Versago Release Notes
Version - 2.5, Build 2.5.7
Release notes are cumulative for all builds of v2.5
Improvements
VGO-2128 - Improved authentication security by removing unnecessary functions from asmx and web
API controllers.
-
VGO-2173 - A vulnerability was addressed were passwords were stored in the password history table in plain text
VGO-2300 - Addressed an issue where a resource Forbidden message was displayed even though the user credentials were correct
Bug Fixes
VGO-2146 - Addressed a vulnerability where an attacker might bypass authentication.
VGO-2148 - Address a vulnerability where information was disclosed in the form of
API documentation.
VGO-2149 - Addressed a vulnerability where access rights at the function level have been verified.
VGO-2150 - Addressed a vulnerability to remote code execution (RCE)
VGO-2151 - Addressed a vulnerability to SQL injection attacks originating from input verification.
VGO-2152 - Addressed CSRF vulnerability.
VGO-2153 - Addressed a vulnerability where the application allowed the upload of an SVG file containing
HTML content.
VGO-2154 - Addressed a vulnerability where references to internal objects were not secure.
VGO-2155 - Addressed a vulnerability denominated Persistent XSS attack where an injected script is permanently stored on the target servers, such as in a database, in a message forum, visitor log, comment field, etc.
VGO-2156 - Addressed a vulnerability where some sensitive data was exposed to attack.
VGO-2157 - Addressed a vulnerability where attacks aim at discovering non-public web services by retrieving their WSDL files.
VGO-2159 - Addressed a vulnerability where by using old session cookies, user profiles can be accessed
VGO-2176 - HTTP is no longer permitted. HTTPS must be deployed with a valid certificate.
VGO-2177 - The session timeout setting for end-users and administrators have been merged. There is only one setting across the site.
VGO-2182 - Some ad blocker extensions to the browser may cause problems with the Admin Console. Please disable any extensions that block the Versago site
-
VGO-2192 - Addressed a vulnerability where several HTTP methods designed to aid developers in deploying and
testing applications were allowed.
VGO-2195 - Addressed a vulnerability where a Referrer-Policy was not being used.
VGO-2196 - Addressed a vulnerability where
HTML comments were exposed.
VGO-2220 - Addressed an issue with reports that allow record submission where the field's length created to store the submission was limited to 50 characters
VGO-2221 - Addressed an issue where action links to an https site were not working properly
VGO-2235 - Mask passwords will no longer be displayed in pages where there is a password field such as DB
connections and Email settings. If the password needs to be changed, the Update Password button must be clicked first in order to enable the field
VGO-2240 - Address an issue where action links did not export correctly. If a form contained multiple action links and it was imported and exported, all links would point to the same link in the new environment
VGO-2247 - Addresses an issue where images in Crystal Reports were not displayed
VGO-2296 - Addressed an issue where system session time out did not follow the set value