Security release to address escaping user input. Webform CiviCRM Integration - Moderately Critical - Cross Site Scripting (XSS) - SA-CONTRIB-2015-160.
#2303503 : fixed potential security issue that could prevent a user from logging out
Login Disable - Access Bypass - Moderately Critical - SA-CONTRIB-2015-162
#2303503 : fixed potential security issue that a user could login even if they shouldn't be allowed to
Security update: Migrate
No bugs reported. Updated core, theme and modules.
This release fixes an issue with the upgrade path to the 7.x-1.5 release that was causing fatal errors for some users. It contains one patch:
In addition to the news page and sub-tabs, all security announcements are posted to an email list. To subscribe to email: log in, go to your user profile page and subscribe to the security newsletter on the Edit » My newsletters tab.
You can also get rss feeds for core, contrib, or public service announcements or follow @drupalsecurity on Twitter.
In order to report a security issue, or to learn more about the security team, please see the Security team handbook page.
If you are a Drupal developer, please read the handbook section on Writing secure code.
Drupal is a registered trademark of Dries Buytaert.