EMS Software, LLC

EMS Kiosk Release Notes V44.1 Update 6

Name: V44.1 Update 6

Release Date: October 18, 2016

Web Traffic Security Vulnerabilities

The web application sent non-secure user and session information (cookies) during encrypted (SSL) sessions, exposing vulnerable information.

Fix: Added ANtiForgery validation to all Ajax HttpPost calls and added verb tampering redirection to prevent non http or Get calls being made to Kiosk so web traffic no longer exposes user and session information.