@ -220,6 +220,21 @@ This version of Chamilo only includes new features:
<li>Removed the "Use document title" option - now we force users to use a document title - this avoids many issues with documents names - see #3781</li>
<li>Removed the "Use document title" option - now we force users to use a document title - this avoids many issues with documents names - see #3781</li>
</ul>
</ul>
<h1>Chamilo 1.8.8.6 - Rottweil, 20th of July 2012</h1>
<h3>Release notes - summary</h3>
<p>Chamilo 1.8.8.6 is a minor security fix, stable version for version 1.8.8.4. If you are using Chamilo 1.8.8.4, we highly recommend you upgrade to this version, either by following the usual upgrade procedure, or by applying a very small patch, as explained on <ahref="http://support.chamilo.org/projects/chamilo-18/wiki/Security_issues">our security issues listing page</a>. The security fixes are all considered "moderate". This means you could loose data (specifically dropbox tool data in this case) and your users might get tricked into providing credentials to potential hackers, but the integrity of your server will not be in direct danger. 1.8.8.6 was developed in a separate branch, but fixes were applied to the 1.9 branch, which means 1.9 can be considered as the follower of 1.8.8.6 as much as of 1.8.8.4. If you have 1.8.8.4, migrating to 1.9 will effectively remove the need for migrating to the intermediary step of 1.8.8.6</p>
<h4>Why Rottweil?</h4>
<p><ahref="https://maps.google.com/maps?q=48.167352,8.627969&hl=fr&ll=48.167352,8.627969&spn=0.006054,0.016512&sll=48.167352,8.627969&sspn=0.006054,0.016512&t=h&z=17">Rottweil</a> is a <ahref="http://en.wikipedia.org/wiki/Rottweil">small medieval German town</a> where the occasional tourist might feel very relaxed and secure. This feeling is increased by the obviously-difficult-to-attack strategical position. Considering the security-only aspect of this release, we wanted a small city name that would represent this more secure aspect. Rottweil has been visited by one of our team members in the past... that's all it takes.</p>
<h3>Fixes</h3>
<ul>
<li>Fixed long-standing e-mail sending bug (fixed in upstream and documented on the forum and all over the internet)</li>
<li>Fixed a reflected XSS PHP_SELF security flax in the phpdocx 3rd-party library - #5202</li>
<li>Fixed an unauthorized file deletion in dropbox by logged in users - #5202</li>
<li>Fixed XSS unfiltered input in dropbox - #5202</li>