Security Enhancements
Release Date: 01/16/24:
Security
- We improved the account lockout functionality to prevent improper password resets as part of the flow.
- We mitigated a vulnerability related to an Insecure Direct Object Reference (IDOR).
- We improved our defense against Cross-Site Scripting (XSS) between Messenger and CXME.
- We hardened the password requirements function to reduce potential vulnerabilities.
- We mitigated a potential account takeover vulnerability related to the password reset flow.
- We improved our defense againt SQL injections throughout the CXME application.
- We improved our file scanner service to block .msi file types.
Admin & Settings
We added a field called 'Restrict Access To Teams' to the add and edit screens of Tags and Categories in Settings. This field can now be left blank and all Teams will have access to the created Tag or Category. If one or more Teams are added to this field, the Tag or Category will only show to users on that Team when accessed from the Details tab of a Case.