-
Type:
Defect (Security)
-
Resolution: Fixed
-
Priority:
Blocker
-
Affects Version/s: None
-
Component/s: Frontend (F)
-
Sprint 19, Sprint 20, Sprint 21, Sprint 22
-
2
Open a link http://monitoring.zabbix.lan/popup.php?srctbl=applications&srcfld1=name&real_hosts=1&dstfld1=application%26quot%3B)%2Balert(%26quot%3BWoooooohooooo!%20XSS!!!%26quot%3B)%2Btrim(%26quot%3B&with_applications=1&dstfrm=zbx_filter and click on any of the links.
Script is executed and we can do anything from there.