Werk #12826: Fix reflected XSS using the on page search
Component | User interface | ||||
Title | Fix reflected XSS using the on page search | ||||
Date | Apr 28, 2021 | ||||
Level | Trivial Change | ||||
Class | Security Fix | ||||
Compatibility | Compatible - no manual interaction needed | ||||
Checkmk versions & editions |
|
The on page search could be used to trigger a reflected XSS attack. It was possible to execute arbitrary javascript code in the context of the user clicking on the reset button of the on page search.