PART A - Development work for this case has been completed. 1. The change will be available in version: 12.40.0429 2. The following changes were made(Include Database object names, Program classes, and any other relevant information): - Removed all Object Exceptions "throw" from public/unsecured pages to prevent hackers from seeing error messages. This includes API pages and "Contact Us", Email Authorisation and "View Attachment" pages.
- Validate public page Query strings for GUID's before processing them - found the issue on one page
- Added CAPTCHA to 2FA if the code entered is incorrect after 1 attempt
3. Affected Areas: - Attachments
- 2FA
- License API
4. The issue was caused by: - Security Compliance
5. Notes: 6. Next Step (Review and System Test (Developer) -> UAT (Quality) -> Documentation): System Test completed. |