|
|
|
@ -1,7 +1,13 @@
|
|
|
|
|
CHANGELOG Roundcube Webmail
|
|
|
|
|
===========================
|
|
|
|
|
|
|
|
|
|
RELEASE 1.2.10
|
|
|
|
|
--------------
|
|
|
|
|
- Fix missing message-htmlpart1 class breaking inline CSS (#6493)
|
|
|
|
|
- Security: Fix XSS issue in handling of CDATA in HTML messages
|
|
|
|
|
- Security: Fix remote code execution via crafted 'im_convert_path' or 'im_identify_path' settings
|
|
|
|
|
- Security: Fix local file inclusion (and code execution) via crafted 'plugins' option
|
|
|
|
|
- Security: Fix CSRF bypass that could be used to log out an authenticated user (#7302)
|
|
|
|
|
|
|
|
|
|
RELEASE 1.2.9
|
|
|
|
|
-------------
|
|
|
|
|