Security Fix (low): Resolved Path Traversal vulnerability in image operations.
Special thanks to Said Garazade for reporting

  • The operation rotate/flip could be applied on a different image when session id and form token is known.
  • Config parameters were not merged with menu parameters. So menu parameters were not active