SuiteCRM 7.9.1 Security & Maintenance Patch Now Available

SuiteCRM 7.9.1 is now available to download.

This release resolves a IMPORTANT Security Vulnerability that effect all releases of SuiteCRM, all users of ALL previous releases are advised to Upgrade to 7.9.1 or 7.8.5 as soon as possible.

[size=4][color=#ff0000]We have updated all affected Upgrade and Installer packs.[/color][/size] This only affect s 7.8.x and 7.9.x releases.

Download here from the SuiteCRM GitHub Repository or visit the official website to find the appropriate upgrade.

Thank you to all community members who logged bugs and contributed to this release.

Special thanks to krzyc for notifying us of the security issue.

We have also updated our Security Process asking the community to send their security issues directly to us via email security@suitecrm.com.

==========

This is a bigger announcement than usual as we would like to address some of the concerns that have been raised by the community. Hopefully this will clarify where the current status of the release is and what is next on the agenda.

This release re-instates some of the higher priority Email functionality that was absent from 7.9.0, bug fixes around Emails module and a security patch which we highly recommend you either upgrade to 7.9.1 or 7.8.5 (LTS) as soon as possible.

Below we will list the included functionality into the 7.9.1 Release and how they function – which may be different than from previous Email Client in 7.8.x. Our current priority is to address the remaining bugs and remaining functionality around Emails but we will let you know (when raised) if that previous functionality from the old Email Client will fully transition into 7.9 or be redesigned to conform to the applications’ layout and structure – which lead to the redesign in the first place.
[color=#ff0088]
[size=4]Reply To, Replay All, Forward and Delete:[/size][/color]
This functionality is essentially how you communicate back to your recipient. This functionality can be done via the Detail View of the Email by the Action Buttons.
You can only delete a non Imported Email via the List View and an Imported Email via Detail View.

[size=4][color=#ff0088]Add Signatures via User Mail Accounts:[/color][/size]
This functionality is different than in the previous email client. A default signature can be set via the User Email Settings (within Profile) or by per Personal Account. There is an additional dropdown when setting/editing a Personal Email Account to select an existing Signature to use. So when you are Composing an Email you can switch between the Mail Account (the From) and the Signature will update accordingly.
[color=#ff0088][size=4]
Import Emails – the ability to Assign To and Relate To via the Emails List and Edit View:[/size][/color]
Again, this functionality is visually different from the previous email client but using the standard user interface as other modules. Within the ListView you can select your target emails and Import via the Bulk Actions button. This will open up a pop up and ask to select the appropriate values.

When an Email has been Imported you are able to alter these fields via the standard Edit View of the Record or using the Subpanels on the DetailView. Subpanels are only visible when an Email has been Imported.

[color=#ff0088][size=4]Flag Emails – Unread, Read, and Priority:[/size][/color]
This functionality is again been redesigned to match the similar interface across the application. The User can select their Emails via the List View and flag them appropriately using the Bulks Action menu.

We currently at the time do not Delete Emails from the imap server.

[color=#ff0088][size=4]Quick Create via Emails:[/size][/color]
This functionality we felt required again to replicate what we have already in the application – the use of the quick create subpanels. As the subpanels already provide this functionality the user will only be able to create new Records via Emails if the Email itself has been imported thus providing access to the subpanels.

[color=#ff0088][size=4]Bugs around Email module:[/size][/color]

  • Body failing to populate when importing
  • Email Template Subject not included when selecting template
  • Issues with Date Created and Created by when Importing

[color=#ff0088][size=4]Other Bugs & Features:[/size][/color]
Please see the Release Notes.

We currently have the following Github issues as our higher priority list which we will be aiming for 7.9.2. Be aware that these priorities may change and we will try to keep them up to date by assignment. 7.9.2 is scheduled to be release no more than 2 weeks from 7.9.1 but if there are higher security issues then it will be released earlier as an intermediary release and then schedule a 7.9.3 (so on and so on).

[color=#ff0088][size=4]High Priority[/size][/color]

  • Security Issues
  • Folders in Email Settings are still visible after deleted the associated Email Account.
  • When Editing the Emails Module ListView via Studio the ListView buttons are not maintained.

[size=4][color=#ff0088]Medium Priority[/color][/size]

  • Can’t sort Emails in Draft Folder
  • Unable to Send Emails within Quotes and Invoice modules
  • When Click Email Compose from Subpanels it picks up wrong focus Addresses
  • Unable to set User Defined SMTP Settings when Sending Emails
  • Some Scenarios Attachment Icon is not visible on ListView

There are lower priorities and other bugs we have raised ourselves but we would like to currently target the highs and mediums and understandably get the key functions under the belt and touch up the minor issues in the sequential releases.

Why we would like to focus on the Emails module (and the other introduced 7.9 features) primarily in these post production release is because we have scheduled dedicated development in 7.10 cycle to focus on the stability of the whole application itself so that means those bugs in github around other modules will be tackled. Though we are not saying to stop raising those issues if you find them in 7.9 but they will not be approached (unless they are security issues) until we have 7.9 new features in a suitable position.

Though what we do want to ask of the community is that if you are able to and do have time for is to assist us with benchmarking the Emails module areas of release. You can do so by working from the ‘hotfix’ branch via our git repo or use the release packages and have a good play around with the system. This open world testing aspect has been vastly missing in all of our releases cycles and we feel that this can be easily resolved by being more open that we need a wide variety of testers and inviting users from the community to test and provide feedback. This is such an important part of sussing out the issues and trying to achieve a satisfactory level of the use cases that exist and thus to make each release more stable than the last.

As a note for future major releases we will be inviting user groups to specifically test betas and release candidates to address the lack of issue raising during our development cycles. This will give you, the community, a more dedicated chance to offer your feedback on features and UI issues and how the in development functionality is shaping up – more importantly you tell us how stable it is or isn’t and that is our priority to produce a product you feel confident with.

Thank you for your feedback so far and hope that you continue to do so to aid us make each release better than the last.

All input is welcome AND HIGHLY ENCOURAGED! :slight_smile:

The SuiteCRM Team.

4 Likes