Werk #2390: Fixed possible XSS issue on views
Component | User interface | ||
Title | Fixed possible XSS issue on views | ||
Date | Jun 30, 2015 | ||
Level | Trivial Change | ||
Class | Security Fix | ||
Compatibility | Compatible - no manual interaction needed | ||
Checkmk versions & editions |
|
It was possible to use the view_name variable to inject HTML/Javascript code into the status GUI views.