Open Atrium - Staff Directory

Hi,

We use Open Atrium 1.08 on our Drupal 6 intranet.

One problem I noticed in the Staff Directory page is that the "Section" drop down list that is being displayed is selecting the distinct sections from all employees. This is not a problem, but after doing some testing I discovered that it also includes previous employees that have had their account suspended. The problem it creates is that if a previous employee belonged to a section that no longer exists, it still shows up in the list and creates confusion for other users.

SA-CONTRIB-2015-021 - Content Analysis - Cross Site Scripting (XSS)

PDF Version link does not work on certain pages

On our website, there are a few pages which we are not able to view the PDF version of the page. It appears that the reason has to do with a setting that does not allow developers to have externally linked photos to show up in a PDF format.

For example, on one page we have an image that is an external photo, but when I click the PDF Version link I get the following error:

SA-CONTRIB-2015-020 - Contact Form Fields - Cross Site Request Forgery (CSRF)

SA-CONTRIB-2015-019 - Ubercart Currency Conversion - Open Redirect

SA-CONTRIB-2015-014 - Wishlist - Multiple vulnerabilities

Pages

Subscribe with RSS Subscribe to RSS - Drupal 6.x