Hardening in 6.5.0 without a known vulnerability

These changes of 6.5.0 close no hole which could be exploited, but they remove weaknesses:

  • New carts and orders get an identifier from a random source instead of one derived from the time. An order can not be looked up by its identifier alone: downloads need a random token, the order tracking needs the email address as well and limits the attempts, and the order page shows only the orders of the logged in user.
  • Three back-end requests - the lists of the content plugin dialog and the count of the missing thumbnails - and sending a test mail from an email template check the form token now. Joomla only lets users with the permission Manage of Event Gallery reach them; the test mail also needs Edit now.
  • The upload page escapes the folder name of the event. A folder name which could carry markup - with <, > or " in it - can not be entered in the event form or come in through the sync.
All prices include VAT. The gross price will vary depending on the selected shipping country.