Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-1340: YetiForce CRM ver. 6.4.0 (#16359) · YetiForceCompany/YetiForceCRM@2c14baa

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

CVE
#xss#web#google#debian#nodejs#js#git#php#pdf#auth#docker

Permalink

Browse files

YetiForce CRM ver. 6.4.0 (#16359)

* Added improvements in record collector

* Integration with UaYouControl.php (#16293)

Co-authored-by: Mariusz Krzaczkowski [email protected]

* Integration with UaYouControl.php (#16293)

* Add external link to NoBrregEnhetsregisteret. (#16292)

* Add external link to NoBrregEnhetsregisteret. #16292

* Add NorthData to RecordCollectors. (#16278)

* Add NorthData to RecordCollectors.

* Change docs.

Co-authored-by: Mariusz Krzaczkowski [email protected]

* Fix #16311

* Added conditions wizard for ‘Update related record’ workflow action

* Add NorthData to RecordCollectors. (#16278)

* Code improvements

* Added improvements in record collector

* Zefix integraion [in progress] (#16281)

* Zefix integraion [in progress]

* ChZefix integration.

Co-authored-by: Mariusz Krzaczkowski [email protected]

* Improved workflow action

* Added improvements in record collector

* Improvements in the store

* Update RecordCollector tests

* Code improvements

* Improved ConfReport

* languages/en-US/Other/RecordCollector.json

* Improved change module type

* Improved default dashboard in api portal

* Fix Send PDF workflow task

* Improved default dashboard in api

* Fixed attachments in ‘Emails to send’ panel

* lib_roundcube 0.3.0 Roundcube Webmail 1.6.0

* tests

* tests

* Update tests.yml

* Added improvements in record collector

* tests/setup/dependency.sh

* .github/workflows/tests.yml

* .github/workflows/tests.yml

* .github/workflows/tests.yml

* Code improvements

* Update dependencies

* Added minor improvements

* tests

* Added improvements in record collector

* Added improvements in record collector

* Added minor improvements

* Added minor improvements

* Added minor improvements

* Improved import file button

* Improved imap connection

* Fix #16317 - list view entries count

* Added minor code improvements

* Improved menu items

* Added improvements in record collector

* Fix gantt view (#15772)

* Added improvements in record collector

* Added improvements in record collector

* Added improvements in record collector

* Updated graphics in store

* Update install translations

* Update fonts

* Improved OSSMail template

* Updated graphics in store

* Update fonts

* tests

* tests Validator

* Update icons

* Improved widgets permissions (#15613)

* Increase scrolling speed (#15031)

* Added tracking to media management

* Added improvements in record collector

* Added improvements in record collector

* Added improvements in record collector

* Added minor code improvements

* tests

* Added minor code improvements

* Fixed #15164 (#16319)

* Some changes in Import module (#16318)

* Code formatting

* Added improvements in record collector

* Change the library “sonata-project / google-authenticator” to “pragmarx/google2fa”

* Update dependencies

* Update dependencies

* Updated *.min and *.map files

* Change the library “sonata-project / google-authenticator” to “pragmarx/google2fa”

* Added minor improvements in Composer::install

* Update dev dependency

* Added dropdown button to record collectors (#16322)

* Corrected Record collectors table width (#16323)

* Fixed #15183 modulesMapRelatedFields don`t work correct for multipicklist

* Added minor improvements in Credits

* Fix edit view header links

* Improved Inventory panel and PDF widget

* Added improvements in record collector

* Added improvements in record collector

* Update install translations

* #16282 Improved the handler from getting coordinates to the map

* Added minor code improvements

* Fixed getting reference module in inventory name field (#16329)

* Missing icons update

* Improved tree field type

* Improved tests and some code

* Fix tree field type

* Fix scheme for tree data table

* Improved switch users

* Improved YetiForce CLI

* [PROD](renovate) Update dependency github/super-linter to v4.9.6 (#16324)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* Bump giggsey/libphonenumber-for-php from 8.12.52 to 8.12.53 (#16331)

Bumps [giggsey/libphonenumber-for-php](https://github.com/giggsey/libphonenumber-for-php) from 8.12.52 to 8.12.53.

  • [Release notes](https://github.com/giggsey/libphonenumber-for-php/releases)
  • [Commits](giggsey/[email protected]…8.12.53)

updated-dependencies:

  • dependency-name: giggsey/libphonenumber-for-php dependency-type: direct:production update-type: version-update:semver-patch …

Signed-off-by: dependabot[bot] [email protected]

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Improved switch users

* Improved switch users

* Unused code has been removed

* Fix tree field type

* Added improvements in record collector

* Improved integration with DAV

* Improved conditions wizard for ‘Update related record’ workflow action

* Fixed focus to search text field when click on select2 drop down in modal window

* Added improvements in record collector

* Added minor code improvements

* Improved ConfReport

* Improved .htaccess

* Added minor code improvements

* Improved ConfReport

* Fix icon on tree field type and change icon management view

* Removed unused code. “Is added” - condition in workflows (#16321)

* Correct setting of check boxes of Inventory boolean fields depending on their values. (#16326)

* Update Inventory.js Now the check-boxes of Inventory boolean fields will be set correctly regarding to their content.

* README.md (#16332)

* Improve inventory auto fill

* Improved getting data from smtp (#16334)

* Fixed #13136 (#16335)

* Improved DB structure for map table cache

* Improved updating payment status (#16327)

* Improved updating payment status

* Corrected translation (#16336)

* Removed translation (#16337)

* A functionality has been added to unlock e-mail accounts

* Fix #13486

* Update dependencies

* mbstring.func_overload

* Added priority to CalendarActivities and OverdueActivities dashboard … (#16276)

* Added priority to CalendarActivities and OverdueActivities dashboard widgets

* Added improvement

* Hidden icon for previewing replies in comments (#16339)

* The display of the multi email field has been improved

* Added working time counter widget. (#16316)

* Added working time counter widget.

* Added translation

* Added improvements

* Removed varialbe

* Corrected comment

* Added title to buttons

* Added type to variable

* Removed redundant characters

* Added working time counter widget. #16316

* Added minor improvements

* Improoved dashboard titles

* Updated *.min and *.map files

* Added minor improvements in languages

* Updated translation

* Improvements have been added to the integration with WAPRO ERP

* Update install translations

* Update translations

* Update translations

* Added improvements in record collector

* Added improvements in record collector

* Improved input data cleanup

* Improved RSS

* Improved Rss

* Update all Yarn dependencies (2022-08-15) (#16344)

Co-authored-by: depfu[bot] <23717796+depfu[bot]@users.noreply.github.com>

* Added improvements in record collector

* Improvements in the mechanism of generating PDF files

* YetiForcePDF update v0.1.40 & Update dependencies

* Improved some config templates

* Added minor improvements

* Remove unnecessary code

* .github/workflows/actions.yml

* .github/workflows/actions.yml

* .github/workflows/tests.yml

* .github/workflows/tests.yml

* .github/workflows/tests.yml

* Improved Db importer/updater

* Added buttons to the Working hours counter widget (#16340)

* Added buttons to the Working hours counter widget

* Added translations

* Improved widget

* Added button lock when starting timing

* Update translations

* Added missing translation

* .github/workflows/tests.yml

* .github/workflows/tests.yml

* .github/workflows/tests.yml

* Added missing translation

* .github/workflows/tests.yml

* Removed Translation (#16347)

Co-authored-by: Radosław Skrzypczak [email protected]

* Update install translations

* Added minor improvement in get actual version of PHP

* Update install translations

* Updated *.min and *.map files

* Redundant code has been removed

* .github/workflows/tests.yml

* .github/workflows/tests.yml

* .github/workflows/tests.yml

* Improved RSS

* Added improvements

* Update DEV dependencies

* Fix Completions initialization in comments widget (#16348)

* Update fonts

* Fixed sending files in API for PUT method

* Update DEV dependencies

* Improved valid of time in Business Hours (#16351)

* Improved executing workflow when an unsupported operator is selected (#16352)

* Improved executing workflow when an unsupported operator is selected

* Improved getting translation (#16350)

* Improved Importer

* Improved working time counter widget

* Improved api

* Expansion of the tests

* Expansion of the tests

* tests

* Update DEV dependencies

* Improved Rss

* tests

* Value display secured

* Added improvements

* Improved index name

* Improved validation of quantity field (#16355)

* Improved validation of quantity field

* Improved code

* Add missing picklist dependencies

* Added validation whether at least one business day has been selected in the Business hours module (#16356)

* Compile js

* Moved swagger file

* Improved swagger generating functions

* Added minor improvements

* Fixed issue with date format

* Added improvements

* Fixed a bug when selecting all users in the calendar quick edit view (#16357)

* Improved swagger generating functions

* Added improvements

* Added improvements

* Added improvements

* Improved Address Search panel

* Improved Emails to send panel

* Fix action name

* Fix description in docBlock

* tests/Settings/ApiAddress.php

* Compile js

* tests/Settings/ApiAddress.php

* tests/Settings/ApiAddress.php

* Remove html unnecessary class

* Fixed #14266 (#16349)

* [PROD](renovate) Update debian Docker tag to v11 (#16341)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* Improved anonymization

* Added improvements

* Update install translations

* Improved config class

* Added improvements

* Improved generatedtype for some fields

* Fixed #15631 (#16358)

* Added improvements

* Improved block sequence

* 6.4.0

Co-authored-by: rembiesa [email protected] Co-authored-by: Radosław Skrzypczak [email protected] Co-authored-by: Adrian Koń [email protected] Co-authored-by: bmankowski [email protected] Co-authored-by: Arek Solek <[email protected]> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Jared Ramon Elizan [email protected] Co-authored-by: depfu[bot] <23717796+depfu[bot]@users.noreply.github.com>

  • Loading branch information

Related news

GHSA-w83m-rghh-frxj: Cross site scripting in yetiforce/yetiforce-crm

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907