This release contains fixes for a couple of security vulnerabilities.
Critical security patches
Fixed an XSS vulnerability in admin mode on Zenario sites where the Location
Manager was running.
Fixed a security vulnerability where an administrator could execute arbitrary
commands on the web server by uploading a crafted file and displaying it via the
Document Container plugin.
Other fixes
- Fixed a bug where edit buttons were incorrectly displayed when viewing
Newsletters that had already been sent.
- Fixed an incorrect confirmation message when trying to duplicate a plugin
inside a nest or slideshow.
- Fixed a bug where the "Make all plugins in nest equal height" option was
offered for nests using the "One or more slides" appearance, which does not
support this feature.
- Fixed an issue where deleting a sitewide plugin left orphaned records in a
linking table, causing bugs on the site.
The full release notes for Zenario 10.3 can be found at zenar.io/zenario-103.