Uploaded image for project: 'ZABBIX BUGS AND ISSUES'
  1. ZABBIX BUGS AND ISSUES
  2. ZBX-22720

Remove possibility to add html into Geomap attribution field (CVE-2023-29452)

XMLWordPrintable

    • Sprint 99 (Apr 2023), Sprint 100 (May 2023)
    • 1

      Currently, geomap configuration (Administration) allows using HTML in the attribution field. This should be changed in the following way:
      1. Default providers should still have static attributions with HTML (but the attribution field shouldn't be shown). Users shouldn't be able to change attribution for default providers.
      2. Custom providers should have the attribution field, but it should be rendered as text (no HTML support) and a hint about trusted sources should also be removed.

            Miks.Kronkalns Miks Kronkalns
            vjaceslavs Vjaceslavs Bogdanovs
            Team B
            Votes:
            0 Vote for this issue
            Watchers:
            10 Start watching this issue

              Created:
              Updated:
              Resolved: