/var/softaculous/rosariosis
Edit: /var/softaculous/rosariosis/changelog.txt (32054B)
Changes in 12.9.3
-----------------
- Security fix #397 Unauthenticated stored XSS: remove HTML tags in SaveReport.php, thanks to @Bradsen
- Only return 403 Forbidden code if not AJAX request in Warehouse.php
- Logout if no Staff or Student session ID when modfunc=first-login in Warehouse.php
Changes in 12.9.2
-----------------
- Fix SQL syntax error "AND STUDENT_ID IN()" when nothing to save in InputFinalGrades.php & EnterEligibility.php
- SQL fix "Enroll student for next school year" when student is inactive in Enrollment.fnc.php
- Fix saving new user when current Staff ID set (in other browser tab) & user has no permission to edit User Profile in User.php
- CSP Do not save violations triggered by VisualSPHost in SaveReport.php
- No user in session yet, send 403 Forbidden (99% chances its a bot) in Warehouse.php
- Fix SQL error retro-compatibility with old Grade Level inputs in GetStuList.fnc.php
- Corrections to the Spanish help texts translation in help.mo
- Security fix #390 Reflected XSS - unescaped reflection into `