Actions
Bug #16923
closed
JP
JP
Potential XSS via inline Firewall Log rule descriptions
Bug #16923:
Potential XSS via inline Firewall Log rule descriptions
Start date:
Due date:
% Done:
100%
Estimated time:
Plus Target Version:
26.07
Release Notes:
Default
Affected Version:
Affected Architecture:
Description
When firewall rule descriptions are enabled in the firewall log (either as a column or row), the rule labels/descriptions are printed to the user without encoding.
Files
Actions