Security innovations

Reject special characters in the backend of user data

When saving user data (first name and last name), the backend did not check for invalid characters, allowing a logged-in attacker to inject HTML code.

Invalid characters in the host field for a filesystem data source

When specifying the path to a filesystem data source, invalid characters were not filtered, allowing an authenticated attacker to inject HTML code.

MI24: Security policy setting to be masked

In the data source settings, MovingImage24 security policies are masked in the same way as passwords.

Extend SecurityToken to include a creation time check

The SecurityToken can now optionally check the token's creation time.

External link Login required
Zuletzt bearbeitet am 29.06.2026 08:06.