Changes
This release includes security fixes. We recommend applying it to every site. If you are on 1.0.2, overwriting the 10 changed files is enough.
We are releasing zittme 1.0.3. It is a maintenance release that ports the security and bug fixes in Rhymix 2.1.38 onto 1.0.2, and it adds no new features. It also fixes the page save error reported on the Q&A board.
Security
- Rhymix patch Widget code blocked in the post body filter — The post body filter now strips widget code. Regular members can no longer load site widgets by putting widget code in a post.
- Rhymix patch Board header and footer text restricted — Board managers who are not site administrators can no longer edit a board's header and footer text. Because these fields can hold scripts, board managers now see them as read-only.
Bug fix
- Rhymix patch Widget and document pages could not be saved — Saving a page no longer fails with the error "the external document path for PC does not exist". Pages that do not use an external path now skip the path check. (Reported by JLPT)
- Rhymix patch Header and footer scripts unescaped twice — Scripts an administrator puts in a board's header or footer were unescaped once more on save, which changed their content. This is fixed.
- Rhymix patch Cursor on read-only language fields — On read-only language fields in the admin, the multilingual button showed a cursor as if it could be edited. The cursor is now correct.
- Rhymix patch Undefined property warning — The undefined property warning written to the error log when loading layout design info is gone.
Version
ZITTME_VERSION 1.0.3RX_VERSION 2.1.38
How to update
There are no database changes, so you only need to overwrite files. Back up your site files before you start.
- Download the file for your version — On 1.0.2, get
zittme-1.0.3-changed.zip(10 changed files). On 1.0.1 or earlier, getzittme-1.0.3.zip(full package). - Check the SHA256 — Make sure the SHA256 of the downloaded file matches the value shown on this page.
- Overwrite your site root — Extract the archive over your site root as is. The
files/folder and config files are not in the zip, so they stay as they are. - Check the version — Go to Admin > Dashboard and check that the version shows 1.0.3. If the screen still looks the same, run Admin > Regenerate cache files once.
Contributors
Thank you to Rhymix for providing the security and bug fix patches.
Thank you to JLPT for the report on the Q&A board. If anything is missing or could be better, please send us your feedback at any time. We will use it to keep improving.
Requirements: GPLv2 · PHP 7.4 or later · MySQL or MariaDB