| Require attention to configuration options? | no |
| Fix problems installing or upgrading to a previous version? | no |
| Introduce features? | no |
| **Fix bugs?** | **yes** |
## <a name="security"></a>Security advisories
-**[CIVI-SA-2019-19](https://civicrm.org/advisory/civi-sa-2019-19-sqli-in-dedupefind)**: SQLI in dedupefind
...
...
@@ -14,6 +26,13 @@ Released November 20, 2019
-**[CIVI-SA-2019-23](https://civicrm.org/advisory/civi-sa-2019-23-incorrect-storage-encoding-for-apiv4)**: Incorrect storage encoding for APIv4
-**[CIVIEXT-SA-2019-02](https://civicrm.org/advisory/civiext-sa-2019-02-xss-in-civicase-v5-extension)**: XSS in CiviCase v5 Extension.
## <a name="bugs"></a>Bugs Resolved
-**([dev/core#1406](https://lab.civicrm.org/dev/core/issues/1406)) Report - Fix Filtering my Member shince in Member Summary Report: (bacport [15894](https://github.com/civicrm/civicrm-core/pull/15894))**
-**([dev/core#1391](https://lab.civicrm.org/dev/core/issues/1391)) Contribution Search - Fix issue where the cancel date was not being loaded which meant that cancelled contributions were not being greyed out: (backport [15893](https://github.com/civicrm/civicrm-core/pull/15893))**
-**([dev/core#1374](https://lab.civicrm.org/dev/core/issues/1374)) Contribution Search - Fix issue where after editing or clicking on the next link on a pager the form values would be lost when running the query and all contributions would be returned (backport [15896](https://github.com/civicrm/civicrm-core/pull/15896))**
-**([dev/core#1409](https://lab.civicrm.org/dev/core/issues/1409)) Additional Payment Form - Remove net amount field as causing problems when entering a refund as net amount wasn't being validated properly and should only be calculated. (backport [15889](https://github.com/civicrm/civicrm-core/pull/15889))**
## <a name="credits"></a>Credits
This release was developed by the following people, who participated in
...
...
@@ -22,4 +41,4 @@ various stages of reporting, analysis, development, review, and testing:
Alan Dixon of Blackfly Solutions; Coleman Watts of CiviCRM; Daniel Compton of
Armadillo Sec Ltd; Eileen McNaughton of Wikimedia Foundation; Kevin Cristiano of
Tadpole Collective; Patrick Figel of Greenpeace CEE; Seamus Lee of Australian
Greens; Tim Otten of CiviCRM
Greens; Tim Otten of CiviCRM; Mark Burdett of Electronic Frontier Foundation;