-
Notifications
You must be signed in to change notification settings - Fork 62
Closed
Labels
osctrl-adminosctrl-admin related changesosctrl-admin related changes🐛 bugSomething isn't workingSomething isn't working
Milestone
Description
A malicious XSS payload can be injected in the environment name, inside the function statsRefresh
:
https://github.com/jmpsec/osctrl/blob/master/admin/static/js/stats.js
Although exploitation would be hard, is better to follow best practices and consider this as a dangerous vulnerability.
Metadata
Metadata
Assignees
Labels
osctrl-adminosctrl-admin related changesosctrl-admin related changes🐛 bugSomething isn't workingSomething isn't working