Hestia Control Panel v1.4.13 Release Notes

  • ๐Ÿ”‹ Features

    • โฌ†๏ธ Introduce UPGRADE_MESSAGE variable to support custom messages in e-mail upgrade notification.

    ๐Ÿ›  Bugfixes

    • ๐Ÿ‘Œ Improve the hostname check to prevent invalid hostnames or the use of an ip address (RFC1178).
    • Prevent CSRF from other domains / websites
    • ๐Ÿ›  Fix #2096 Hostname SSL got overwritten by mail.hostname.com certificate
    • โž• Add small wait for /usr/bin/iptables-restore Forum + Fixed v-add-firewall / v-delete-firewall function (#2112) @myrevery
    • ๐Ÿ›  Fix bug in v-change-sys-api. When using v-change-sys-api remove and then v-change-sys-api enable + custom release branch the resetting of api failed + no "error" output was producted
    • ๐Ÿ‘Œ Improve error reporting PMA Single sign on function function
    • ๐Ÿ›  Fixed an issue in v-change-web-domain-name where webserserver where not able to start because old config files where not propperly deleted #2104
    • ๐Ÿ›  Fixed potential XSS vulnerability in /list/keys/ @wtwwer Disclosure
    • โœ‚ Removed /edit/file as it has been replaced by Filegator and part of the old Vesta Filemanager
    • ๐Ÿ›  Fixed potential External control / path vulnerability in /add/package @wtwwer Disclosure
    • โž• Add extra checks to prevent type juggling @vikychoi Disclosure
    • ๐Ÿ‘Œ Improved and updated some missing translation strings @myrevery
    • ๐ŸŒ Sync translations with Github