-
Defect (Security)
-
Resolution: Fixed
-
Trivial
-
6.0.17, 6.4.2, 7.0.0alpha1
-
Sprint 99 (Apr 2023), Sprint 100 (May 2023)
-
1
Currently, geomap configuration (Administration) allows using HTML in the attribution field. This should be changed in the following way:
1. Default providers should still have static attributions with HTML (but the attribution field shouldn't be shown). Users shouldn't be able to change attribution for default providers.
2. Custom providers should have the attribution field, but it should be rendered as text (no HTML support) and a hint about trusted sources should also be removed.
- is duplicated by
-
ZBX-22981 Possibility to add html code into Geomap attribution field (CVE-2023-29452)
- Closed