Check_MK Werk 3970: Fixed possible URL injection on index page

Lars Michelsen lm at mathias-kettner.de
Mon Oct 24 10:06:39 CEST 2016


ID:          3970
Title:       Fixed possible URL injection on index page
Component:   Multisite
Level:       1
Class:       Security Fix
Version:     1.4.0i2

Till this version it was possible to inject authenticated users external URLs
as start URLs for their GUI.

An attacker could use this to make an authenticated GUI user open a page of his
choice when the user clicks on a prepared link.

One example URL which could be used: "index.py?start_url=//heise.de".



More information about the checkmk-werks-lvl1 mailing list