Fixed
Details
Assignee
Guus der KinderenGuus der KinderenReporter
Dan CaseleyDan CaseleyLabels
Fix versions
Priority
Major
Details
Details
Assignee
Guus der Kinderen
Guus der KinderenReporter
Dan Caseley
Dan CaseleyLabels
Fix versions
Priority
Created September 23, 2019 at 4:18 PM
Updated September 24, 2019 at 12:49 PM
Resolved September 24, 2019 at 12:49 PM
LDAP Settings page (/ldap-server.jsp) is susceptible to XSS - a {{<script>}} tag entered into the BaseDN setting here will be rendered on Server Settings → Profile Settings (/profile-settings.jsp)