Patch #1 Released for V2.4.1

Friday, January 13, 2017 Tags: patch, release, bugs

This patch fixes several issues in the v2.4.1 release especially mailing failures and a security vulnerability in the elFinder file manager.. We strongly encourage all Exponent installations be upgraded to v2.4.1 with this patch as soon as practical! Patch #1 to v2.4.1 is found at http://sourceforge.net/projects/exponentcms/files/exponent-2.4.1-patch-1.zip/download

v241patch1 adds no features to v241:

v241patch1 fixes these issues in v241:

  • fix fatal crash when sending emails
  • Unrestricted File Deletion / Upload Vulnerability in elFinder, reported by mm

v241patch1 updates these 3rd party libraries in v241:

  • update tinymce to v4.5.2
  • update ckeditor to v4.6.2
  • update elFinder to v2.1.20
  • update mediaelement.js to v2.23.5