
A security-focused patch — hardening quote status changes and abuse reports against misuse — plus a rendering fix for quotes whose products have been deleted.
Privacy and security
- Fix: Required login and quote ownership before a quote’s status can be changed, blocking unauthorized status changes.
- Fix: Sanitized and escaped the abuse report description to prevent stored cross-site scripting (XSS) in abuse reports.
Storefront
- Fix: The Request for Quotation quote details page now renders correctly when a quoted product has been deleted, skipping the removed line item.