---
title: Version 1.2.0 Release Notes
description: This release contains minor security and bug fixes.
image: https://knowledge.wiserfunding.com/hubfs/Wiserfunding%20Logo%20-01%20(3).png
---

[Skip to content](https://knowledge.wiserfunding.com/version-1.2.0-release-notes#main-content)

English

Show submenu for translations

[File a support ticket](https://knowledge.wiserfunding.com/kb-tickets/new?hsLang=en)

![Logo\_Wiserfunding Logo -01-2.png\]](https://knowledge.wiserfunding.com/hs-fs/hubfs/Logo_Wiserfunding%20Logo%20-01-2.png?height=50&name=Logo_Wiserfunding%20Logo%20-01-2.png)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [File a support ticket](https://knowledge.wiserfunding.com/kb-tickets/new)
- wiserfunding.com

 wiserfunding.com

 Hello. How can we help you?

- There are no suggestions because the search field is empty.

1. [Help Centre](https://knowledge.wiserfunding.com/?hsLang=en)
2. [Platform Release Notes](https://knowledge.wiserfunding.com/platform-release-notes?hsLang=en)

# Version 1.2.0 Release Notes

## This release contains minor security and bug fixes.

### Bug Fixes

#### Typo in graph labels

EBITDA had been mis-typed as EBTIDA in some static text.

#### Security Fixes

The following security fixes were implemented in this release.

#### JSON Web Token Signature

We improved our verification of the token payload.

#### HMAC Secret

We increased the complexity of the HMAC secret.

#### Mass Assignment

The /users endpoint was modified to prevent malicious users altering additional fields.

#### Reset Password Token Expiry

We have reduced the expiry timeout on reset password tokens to 48 hours.

#### Cross-origin Resource Sharing: Arbitrary Origin Low Trusted

Browsers are now instructed to only trust same-origin responses to prevent theoretical exploits such as framing the Wiserfunding portal inside another website.

#### Clickjacking: X-Frame-Options Header Missing

Clickjacking (User Interface redress attack, UI redress attack, UI redressing) is a malicious technique of tricking a Web user into clicking on something different from what the user perceives they are clicking on, thus potentially revealing confidential information or taking control of their computer while clicking on seemingly innocuous web pages.

#### Content Security Policy (CSP)

Content Security Policy (CSP) is an added layer of security that helps browsers to detect and mitigate certain types of attacks, including Cross Site Scripting (XSS) and data injection attacks. The policy tells the browser what resources it is allowed to load for that page.

#### Referrer Policy Header Missing

Referrer Policy controls behaviour of the Referrer header, which indicates the origin or web page URL the request was made from. The Referrer-Policy header helps browsers not leak user information to third-party sites.

#### X-XSS-Protection Header Missing

The HTTP X-XSS-Protection response header is a feature of modern browsers that allows websites to block XSS auditors which could be used for a Cross-Site Scripting (XSS) attack.

---

 

- [Using the Wiserfunding Platform](https://knowledge.wiserfunding.com/using-the-wiserfunding-platform?hsLang=en#main-content)

    - [Running New Reports](https://knowledge.wiserfunding.com/using-the-wiserfunding-platform?hsLang=en#running-new-reports)
    - [Updating Reports | Adding More Data](https://knowledge.wiserfunding.com/using-the-wiserfunding-platform?hsLang=en#updating-reports-adding-more-data)
    - [WiserAI Documents](https://knowledge.wiserfunding.com/using-the-wiserfunding-platform?hsLang=en#wiserai-documents)
    - [Portfolio Management](https://knowledge.wiserfunding.com/using-the-wiserfunding-platform?hsLang=en#portfolio-management)
    - [Using Wiserfunding APIs](https://knowledge.wiserfunding.com/using-the-wiserfunding-platform?hsLang=en#using-wiserfunding-apis)
    - [Integrations](https://knowledge.wiserfunding.com/using-the-wiserfunding-platform?hsLang=en#integrations)
    - [General](https://knowledge.wiserfunding.com/using-the-wiserfunding-platform?hsLang=en#general)
- [Understanding the Credit Insights](https://knowledge.wiserfunding.com/understanding-the-credit-insights?hsLang=en)
- [Create Users | Passwords | Contact Support](https://knowledge.wiserfunding.com/create-users-passwords-contact-support?hsLang=en#main-content)

    - [Contact Support](https://knowledge.wiserfunding.com/create-users-passwords-contact-support?hsLang=en#contact-support)
    - [Admin](https://knowledge.wiserfunding.com/create-users-passwords-contact-support?hsLang=en#admin)
- [Platform Release Notes](https://knowledge.wiserfunding.com/platform-release-notes?hsLang=en#main-content)

    - [API Versioning Policy](https://knowledge.wiserfunding.com/platform-release-notes?hsLang=en#api-versioning-policy)

[![Chill listening crop-3](https://knowledge.wiserfunding.com/hs-fs/hubfs/Favicon-1.png?width=23&height=24&name=Favicon-1.png "Chill listening crop-3")](http://wiserfunding.com?hsLang=en)

<https://www.linkedin.com/company/wiserfunding/> <https://twitter.com/wiserfunding> <https://www.facebook.com/wiserfunding/>

Copyright © 2026, Wiserfunding Ltd