Werk #10242: Fix possible XSS using titles of custom snapins
| Component | User interface | ||||
| Title | Fix possible XSS using titles of custom snapins | ||||
| Date | Sep 27, 2019 | ||||
| Level | Trivial Change | ||||
| Class | Security Fix | ||||
| Compatibility | Compatible - no manual interaction needed | ||||
| Checkmk versions & editions |
|
Authenticated users that are allowed to configure and share custom snapins could inject arbitrary JS code to all users which are permitted to view this snapin.