Werk #6610: Fixed possible XSS using the dokuwiki snapin
Component | User interface | ||||||
Title | Fixed possible XSS using the dokuwiki snapin | ||||||
Date | Sep 13, 2018 | ||||||
Level | Trivial Change | ||||||
Class | Security Fix | ||||||
Compatibility | Compatible - no manual interaction needed | ||||||
Checkmk versions & editions |
|
The content of the DokuWiki page named "sidebar" was inserted into the DokuWiki view of Check_MK, but was is not correctly sanitized. This can only be done by an administrator of the page, but every user who can access the DokuWiki view was affected by the vulnerability.