Today, we are pleased to release EShop Shopping Cart 5.6.1. This release addresses some security issues and improvements to make EShop works safe:
1. PDF Invoice / Packing Lists / Shipping Label Security
On previous versions, PDF Invoice / Packing Lists / Shipping Label of orders maybe accessable and downloaded by anyone if they know the path to file. Now, extra validation / security are added, the file name is also generated randomly use token so they are secure and safe.
2. Improved Protection Against SQL Injection.
This release improves user input data validation to help prevent unauthenticated blind SQL injection risks in validation processes. Input data is now handled more securely before being processed by the system.
We recommend updating EShop to version 5.6.1 as soon as possible to ensure your site benefits from these security fixes.
Sincerely, Giang