Release notes 

Eventum 2.3.1 fixes a XSS bug on several pages throughout Eventum. See http://www.zeroscience.mk/en/vulnerabilities/ZSL-2011-4989.php and https://bugs.launchpad.net/eventum/+bug/706385 for more details.

It also includes other bug fixes and minor feature improvements, please see the changelog for more details.


View the full changelog

- Improve getCustomFieldWeeklyReport (merge request 31659)
- Update Smarty 2.6.18 -> 2.6.26 (Elan Ruusamäe)
- Put 'Release' in the 'The issue was updated by' e-mail (Robbert-Jan Roos)
- Changed ereg to preg_match in template helper for compatability (Bryan)
- Removed assignment by reference in db helper to prevent PHP warning (Bryan)
- Fix problem with custom field validation (Bryan) [lp#628862]
- Allow using GET parameters in reports/weekly.php (Elan Ruusamäe)
- Added workflow method to supply custom Link_Filter rules. Supports also callbacks (Elan Ruusamäe)
- Changed 'recieved' to 'received' (Robbert-Jan Roos)
- XSS Fix: escape issue_id in templates accessing it directly via {$smarty.get.id} (Elan Ruusamäe)
- Fix bug with ajax dynamic custom fields not honoring "hideWhenNoOptions" (Bryan Alsdorf) [lp#641133]
- Make attachment names linked in issue Initial Description (Elan Ruusamäe)
- Set memory limit to ~2GiB to be able to download 10MiB emails (Elan Ruusamäe)
- Use KiB, MiB keywords for filesizes (Elan Ruusamäe)
- Rework Mail_Queue code to be memory efficent by fetching only one email a time to memory (Elan Ruusamäe)
- Fix xmlrpc server missing global $XML_RPC_erruser (Elan Ruusamäe)
- Add better xmlrpc client class and sample (Elan Ruusamäe)
- Rewritten monitor script and class with modern code and flexible (Elan Ruusamäe)
- Support for configuring Monitor preferences (Elan Ruusamäe)
- Fix user group when creating new user (Elan Ruusamäe) [lp#691398]
- Allow translating 'Re: ' in email subjects (Elan Ruusamäe)
- Add 'Subscribe Me' button to issue details screen for quickly add user itself to default notification options (Elan Ruusamäe)
- Fix charset when processing Mime_Helper::fixEncoding (replaced by decodeQuotedPrintable)
- Recognize Italian reply prefix in mail subject (Harri Porten)
- Show summary of users time tracking if there are more than one user timetracking record (Raul Raat)
- Fixed bug with quoting email addresses when they are surrounded by < > (Bryan Alsdorf)
- Fixed XSS vulnerabilities in advisory ZSL-2011-4989 (Gjoko Krstic, Bryan, Elan Ruusamäe) [lp#706385] http://www.zeroscience.mk/en/vulnerabilities/ZSL-2011-4989.php

