Still on Drupal 7? Security support for Drupal 7 ended on 5 January 2025. Please visit our Drupal 7 End of Life resources page to review all of your options.
This release is absolutely critical for all users of CCK Slideshow. It addresses an issue where the admin settings page is openly available to all users of your site (even anonymous).
#180568 (SA-2007-021) by hunmonk: Fix XSS holes in project subscription forms. #177312 by hunmonk: add project links, fix breakage on issue subscription form. #168650 by pwolanin, hunmonk: fix improper use of %s
#180568 (SA-2007-021) by hunmonk: Fix XSS holes in project subscription forms. #177312 by hunmonk: add project links, fix breakage on issue subscription form. #168650 by pwolanin, hunmonk: fix improper use of %s
#180568 (SA-2007-021) by hunmonk: Fix XSS holes in project subscription forms. #177312 by hunmonk: add project links, fix breakage on issue subscription form. #168650 by pwolanin, hunmonk: fix improper use of %s #172327 by hunmonk: INSTALL.txt outdated
This release addresses an access bypass security issue, DRUPAL-SA-2007-020. Sites that try to restrict access to issues based on the 'access project issues' or 'access own project issues' permissions should upgrade immediately.