quiz 6.x-4.5

Security update
New features
Bug fixes

Fixes a couple of security problems where users with permission to see other users answers also are able to delete other users answers, and also the default views provided with the module doesn't have any default permission checking. See SA-CONTRIB-2013-083 - Quiz - Access Bypass for more information.

Additionally:
1. Issue #1952498 by caesius: Fixed When auto-revisioning is turned off, module should respect content type revision configuration.
2. Added feedback field specific to user answer.

quiz 7.x-4.0-beta2

Security update
New features
Bug fixes

Important: This version changes access control for quiz questions. Make sure access to creating, editing and viewing quiz questions is as expected after updating to this version.

Fixes a couple of security problems where users with permission to see other users answers also are able to delete other users answers, and also the default views provided with the module doesn't have any default permission checking.

monster_menus 7.x-1.15

Security update
Insecure

Fix an access bypass which could allow even anonymous users to view node comments they should not be permitted to see.

SA-CONTRIB-2013-086 - Monster Menus - Access bypass

bean 7.x-1.5

Security update

Bean 7.x-1.5, 2013-10-23
---------------------------
Fix for SA-CONTRIB-2013-082 - Bean - Cross Site Scripting (XSS) by FrancescoQ, DamienMcKenna: Fixed arbitrary tag in the bean title input.

spaces 6.x-3.7

Security update

Fix for SA-CONTRIB-2013-081 - Spaces - Access bypass

Fix moving of group content for deleted of spaces og spaces enabled group so that it is moved instead of orphaned.

simplenews 7.x-1.1

Security update

This is a maintenance release for Simplenews 7.x-1.x that includes a number of bugfixes including a fix for a security issue, see SA-CONTRIB-2013-080 -Simple News - Cross Site Scripting (XSS) for details.

Changes since 7.x-1.0:

Pages

Subscribe with RSS Subscribe to RSS - Security update