Security Fix (low): Resolved Path Traversal vulnerability in image operations.
Special thanks to Said Garazade for reporting
- The operation rotate/flip could be applied on a different image when session id and form token is known.
- Config parameters were not merged with menu parameters. So menu parameters were not active
