--- - branch: MAIN date: Wed Jul 2 09:13:02 UTC 2014 files: - new: '1.8' old: '1.7' path: pkgsrc/www/php-sugarcrm/Makefile pathrev: pkgsrc/www/php-sugarcrm/Makefile@1.8 type: modified id: 20140702T091302Z.9df830b7f23fc5692b58c5bbca2e1a7d03cd64e3 log: | Update php-sugarcrm to 6.5.17, security release. Quote from http://www.providentcrm.com/news/sugarcrm-6-5-17-patch-list/. 1. Module scanner now blocks two additional functions: simplexml_load_file and simplexml_load_string 2. JS Security Fix in Emails -- changing AJAX call from GET to POST. 3. XML Handling -- Additional error handling and libxml_disable_entity_loader is now set to true. 4. Users module -- Additional checking on un-authorised access to other users profile, plus Bugfix for password field. module: pkgsrc subject: 'CVS commit: pkgsrc/www/php-sugarcrm' unixtime: '1404292382' user: taca