-
Type:
Defect (Security)
-
Resolution: Fixed
-
Priority:
Critical
-
Affects Version/s: 4.0.0alpha1
-
Component/s: Frontend (F)
-
Sprint 19, Sprint 21, Sprint 22
-
0.5
Guest can open script execution link, for example /scripts_exec.php?hostid=10084&scriptid=1
So guest can change script and host ids to see confidential information, for example host ip
Thanks to vjaceslavs