-
Bug
-
Resolution: Done
-
Major
-
None
-
None
-
JBPAPP_5_0
-
Release Notes
Inputs passed to the "monitorName", "objectName", "attribute", and "period" parameters in createSnapshot.jsp and to the "monitorName", "objectName", "attribute", "period", and "threshold" parameters in createThresholdMonitor.jsp are not sanitized before being returned to the user. This can be exploited to allow arbitrary HTML and script code to be executed in a user's browser.
(See bz#510023: https://bugzilla.redhat.com/show_bug.cgi?id=510023 )