We checked the UMC module UCR and found two ways to inject HTML into the module. It's not client to server injection but we should fix it. Gitlab issue is URL field above.
Package: univention-management-console-module-ucr Version: 11.1.1 Branch: 5.2-0 Scope: errata5.2-1 Package: univention-web Version: 6.0.10 Branch: 5.2-0 Scope: errata5.2-1 univention-web.yaml f0a6a7062f14 | fix(univention-management-console-module-ucr): XSS in UMC UCR univention-web (6.0.10) f0a6a7062f14 | fix(univention-management-console-module-ucr): XSS in UMC UCR univention-updater (10.0.53-4) r58279 | Bug #37573: adjusted the styling for the updater dialog. univention-management-console-module-ucr.yaml f0a6a7062f14 | fix(univention-management-console-module-ucr): XSS in UMC UCR univention-management-console-module-ucr (11.1.1) f0a6a7062f14 | fix(univention-management-console-module-ucr): XSS in UMC UCR - Tooltip messages of input fields are now escaped. - The UMC UCR module now escapes UCR keys.
QA: OK: Tooltip messages of input fields are now escaped. OK: The UMC UCR module now escapes UCR keys. OK: advisory
<https://errata.software-univention.de/#/?erratum=5.2x105> <https://errata.software-univention.de/#/?erratum=5.2x106>