Werk #5632

TitleFixed XSS when rendering values of dropdown choices
Date2018-01-10 16:16:40
Check_MK EditionCheck_MK Raw Edition (CRE)
Check_MK Version1.4.0p24,1.5.0i3
Level1 - Trivial Change
ClassSecurity Fix
CompatibilityCompatible - no manual interaction needed

When using the WATO configuration it was possible to create e.g. a service level definition with javascript code in it's alias. When this definition was configured in a rule of the ruleset "Service Level of Hosts", the javascript code could be executed in the browsers context of the user viewing the rule.

The insertion of the javascript code is only possible for authenticated users with the permission to configure Check_MK.