This week we have releases of both the 1.0 and 1.1 versions of Totara, which both include a number of security fixes.
Here's the 1.0.35 changelog:
Release 1.0.35 (3 April 2012): ================================================== Security fixes: T-9666 XSS vulnerability in forum posts for IE users T-9661 XSS vulnerability in course category description T-9663 XSS vulnerability in grades CSV upload T-9660 XSS vulnerability in plan course search dialog Database upgrades: T-9648 Remove last reference to legacy capability Improvements: T-8485 Additions to Chinese, Dutch, Finnish, Hebrew, Hungarian and Polish language packs Bug fixes: T-9670 Fix waitlisted date in report source T-9671 Fix join pruning logic T-9651 Update feedback preprocessor to work with new feedback module T-9657 Fix issue with display of activity groups table T-9658 Fix updating of course cache when indenting on course page T-9655 Add filters to my teammembers embedded report T-6710 Fix missing lang string in progress bar T-9664 Fix cleaning issue with scale values T-9647 Fix issue with multi-day calendar events
And here's the 1.1.14 changelog:
Release 1.1.14 (3 April 2012): ================================================== Security fixes: T-9666 XSS vulnerability in forum posts for IE users T-9661 XSS vulnerability in course category description T-9663 XSS vulnerability in grades CSV upload T-9660 XSS vulnerability in plan course search dialog Database upgrades: T-9672 Fix user profile columns/filters Resolves a bug introduced in 1.1.13 T-9648 Remove last reference to legacy capability New features: T-9656 Add position/organisation content restrictions to user report Improvements: T-8485 Additions to Chinese, Dutch, Finnish, Hebrew and Hungarian language packs T-9669 SQL query optimisation T-9662 Retain more of current sort order in fix_sortthreads Bug fixes: T-9650 Fix issue with waitlisted session and approval T-9670 Fix waitlisted date in report source Now the report doesn't display an erroneous date for waitlisted sessions. T-9671 Fix join pruning logic T-9651 Update feedback preprocessor to work with new feedback module T-9664 Fix cleaning issue with scale values T-9646 Fix ssl detection in qualified_me() T-9658 Fix updating of course cache when indenting on course page T-9619 Fix CAS authentication with ssl loadbalancer T-9655 Add filters to my teammembers embedded report T-9645 Change PARAM_FILE to PARAM_PATH to stop leading slashes being stripped T-6710 Fix missing lang string in progress bar T-7189 Updated CHANGELOG to include API change T-9657 Fix issue with display of activity groups table T-9647 Fix issue with multi-day calendar events
Simon