Dear Users,
SDP 9425 has been released and can be downloaded from the URL below,
Vulnerability
SD-61216 : Cross site scripting vulnerability in change password.
SD-73218 : Information disclosure vulnerability in Contact Support section under Help.
SD-73219 : Cross site scripting vulnerabilities in Language section of the Personalization menu.
SD-73928 : XSS vulnerability in Personalization menu.
SD-73929 : XSS vulnerability in View All Requesters API.
SD-70638 :
Vulnerability :
Inappropriate use of HTTP methods while resetting user password.
Please refer to the below link for the steps to install the patch.
Regards,
Edwin Vasantha Kumar
Servicedesk Plus Team