List of Changes for Forms 10.4.5 Hotfix 1014318

September 7, 2021 | KB: 1014318
Forms 10.4.5

Summary

This article details the list of changes for Laserfiche Forms 10.4.5 Hotfix 1014318.

The following changes have been made to address the Laserfiche Forms Portal File Upload Vulnerability.

  • Public users no longer have the option to download a copy of the file that they uploaded when returning to a saved draft or after submission. (324708, 339722)
  • Enhancements to prevents files types not in the "File extensions allowed" option from being uploaded. (298692)

The update includes the following files:

  • \Config\bin\ar\FormsResource.resources.dll (10.4.5.316)
  • \Config\bin\EntityModels.dll (10.4.5.316)
  • \Config\bin\es\FormsResource.resources.dll (10.4.5.316)
  • \Config\bin\Forms.Persistence.EntityFramework.dll (10.4.5.316)
  • \Config\bin\FormsCommonUtils.dll (10.4.5.316)
  • \Config\bin\FormsResource.dll (10.4.5.316)
  • \Config\bin\fr\FormsResource.resources.dll (10.4.5.316)
  • \Config\bin\pt-BR\FormsResource.resources.dll (10.4.5.316)
  • \Config\bin\th\FormsResource.resources.dll (10.4.5.316)
  • \Config\bin\zh-hans\FormsResource.resources.dll (10.4.5.316)
  • \Config\bin\zh-hant\FormsResource.resources.dll (10.4.5.316)
  • \Forms\bin\ar\FormsResource.resources.dll (10.4.5.316)
  • \Forms\bin\E-Forms.dll (10.4.5.316)
  • \Forms\bin\EntityModels.dll (10.4.5.316)
  • \Forms\bin\es\FormsResource.resources.dll (10.4.5.316)
  • \Forms\bin\Forms.Persistence.EntityFramework.dll (10.4.5.316)
  • \Forms\bin\FormsCommonUtils.dll (10.4.5.316)
  • \Forms\bin\FormsResource.dll (10.4.5.316)
  • \Forms\bin\fr\FormsResource.resources.dll (10.4.5.316)
  • \Forms\bin\pt-BR\FormsResource.resources.dll (10.4.5.316)
  • \Forms\bin\th\FormsResource.resources.dll (10.4.5.316)
  • \Forms\bin\zh-Hans\FormsResource.resources.dll (10.4.5.316)
  • \Forms\bin\zh-Hant\FormsResource.resources.dll (10.4.5.316)
  • \Forms\js\app\form-builder\form-layout.directive.js (Last Modified 8/31/2021)
  • \Forms\js\form\newfileupload.js (Last Modified 8/31/2021)
  • \Forms\js\templates\partial.template.js (Last Modified 8/31/2021)
  • \Forms\Partials\FormsDesigner\_FieldEditMenu.html (Last Modified 8/31/2021)
  • \Forms\Views\Designer\FormBuilder.cshtml (Last Modified 8/31/2021)

Resolution

Click the following link to download a ZIP file containing Hotfix 1014318 for Laserfiche Forms 10.4.5.

KB1014318.zip

  1. Extract the executable file from the ZIP file to a temporary location on the server hosting Laserfiche Forms 10.4.5.
  2. Stop the Laserfiche Forms Routing Service.
  3. Run the installer to update Forms.
  4. Start the Laserfiche Forms Routing Service.

Known Issues

  • A public user may receive an error when resaving their draft again on resume/recover if there is already a previously uploaded file and the file upload field has a configured set of allowed file extensions. The public user can delete the file, reupload the file, and then save. (340734)

Related Links

Release Notes for Laserfiche Forms 10.4.5.

List of Changes for Forms 10.4.5.