Hestia Control Panel v1.6.5 Release Notes

  • 🛠 Bugfixes

    • ➕ Add missing translation strings (#2778 @myrevery)
    • ➕ Add check if folder exists in v-change-web-domain-docroot (#2778)

    🔒 Security

    • 👌 Improve random bytes generator (#2774)
    • 💻 Don't allow /inc/2fa/secret.php called from the web browser directly (#2784 @mayappear)
    • 👌 Improve CSRF Origin Check Bypass (#2785 @mayappear)
    • 🛠 Fix vulnerability in Dokuwiki Quick Install App @redstarp2 (CVE-2022-2550)
    • 🛠 Fixed an issue where custom ports where not saved on restart fail2ban service making Hestia login screen vulnerable for brute force

    Dependencies

    • ⚡️ Update Filegator to 7.8.2