Forum Moderators: DixonJones
It is easy for an attacker to insert arbitrary strings into any web
server logfile. If these strings are then analysed by analog, they can
appear in the report. By this means an attacker can introduce
arbitrary Javascript code, for example, into an analog report produced
by someone else and read by a third person.
Stephen Turner recommends upgrading to version 5.22 immediately.
[analog.cx...]