This release contains fixes for a couple of security vulnerabilities.

Critical security patches

Fixed an XSS vulnerability in admin mode on Zenario sites where the Location
Manager was running.

Fixed a security vulnerability where an administrator could execute arbitrary
commands on the web server by uploading a crafted file and displaying it via the
Document Container plugin.

Other fixes

  • Fixed a bug where edit buttons were incorrectly displayed when viewing
    Newsletters that had already been sent.
  • Fixed an incorrect confirmation message when trying to duplicate a plugin
    inside a nest or slideshow.
  • Fixed a bug where the "Make all plugins in nest equal height" option was
    offered for nests using the "One or more slides" appearance, which does not
    support this feature.
  • Fixed an issue where deleting a sitewide plugin left orphaned records in a
    linking table, causing bugs on the site.

The full release notes for Zenario 10.3 can be found at zenar.io/zenario-103.