Dear Users,
SDP 10020 has been released and can be downloaded from the URL below,
Issues Fixed
Vulnerability :
SD-77126 : Reflected XSS vulnerability found in all listviews.
Requests :
SD-77989,SD-78062 : In some scenarios, adding or editing a request resolution with content size more than 16kB causes out of memory crash.
Admin :
SD-77842 : When a user enters a valid email address while configuring Incoming EWS server, "Invalid email address" alert is thrown. The issue occurs if the second part (usually ".com") of the email id has more than 4 characters.
Reports :
SD-77943 : Privilege escalation vulnerability found in custom query report.
SD-78061 : Under Reports >> New Query Report, access to tables containing users' sensitive information via direct and encoded queries is restricted.
Please refer to the below link for the steps to install the patch.
Regards,
Edwin Vasantha Kumar
Servicedesk Plus Team