This release contains several bug fixes, improvements and security-related changes since Admidio 5.0.16.
Security
Security is an important part of this release. Two issues have been fixed to improve the protection of server files and prevent unauthorized changes to event registrations.
-
Improved security when sending eCards
Fixed a vulnerability that could allow authenticated users to access local server files through images embedded in eCard messages. -
Improved validation of event registrations
Fixed an issue where members could register additional guests even when this option was disabled, potentially exceeding event capacity and preventing other members from registering.
You can find more information here:
https://github.com/Admidio/admidio/security
Bug Fixes
- Fixed an issue where dynamically loaded buttons did not correctly submit CSRF tokens, affecting actions such as creating new contacts.
- Fixed an issue where rejected chunked file uploads could be repeated indefinitely without displaying an error message.
- Fixed an issue where certain Docker environment variables, including
ADMIDIO_LOGIN_FOR_UPDATEandADMIDIO_PASSWORD_HASH_ALGORITHM, were not applied correctly. - Fixed an issue that could cause duplicate entries to appear when adding participants to events.
- Corrected several typos and inconsistent translations in the German language files.
Improvements
- Updated MIME type definitions for various audio, video and Microsoft Office file formats to improve compatibility with browsers and downloads.
- Improved error handling for large file uploads to ensure that rejected uploads are stopped and appropriate error messages are displayed.
Further Information
We recommend you to read our announcements for version 5 if you have not done so already:
https://www.admidio.org/dokuwiki/doku.php?id=en:2.0:announcement_v5
A full list of all new features and bug fixes can be found in our [issue tracker for version 5.0.17](https://github.com/Admidio/admidio/issues?q=is%3Aclosed%20milestone%3A%22v5.0.17%22).
Full Changelog:
https://github.com/Admidio/admidio/compare/v5.0.16..v5.0.17
If you are new to Admidio and want to install it on your website, the following wiki page could help you:
https://www.admidio.org/dokuwiki/doku.php?id=en:2.0:installation
The following wiki page may be interesting when updating an existing installation:
https://www.admidio.org/dokuwiki/doku.php?id=en:2.0:update
Contributors
A big thank you to everyone who contributed to this release by reporting bugs, suggesting improvements, or providing fixes.
Special thanks to:
Your contributions help make Admidio better with every release. Thank you for your support!