From c3321a2aa95195d20e11314cbf7c949c9a19d963 Mon Sep 17 00:00:00 2001 From: duffyduck Date: Mon, 1 Jun 2026 18:29:08 +0200 Subject: [PATCH] Pentest 48.1 MEDIUM + 50.1 MEDIUM: customerEmailLabel-Strip + SSRF strict MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 48.1 (XSS in customerEmailLabel): - Neuer sanitizeCustomerEmailLabel-Helper (stripHtml + trim + 60-Zeichen-Cap) - Eingesetzt in createProviderConfig + updateProviderConfig (Write-Pfad) und getProviderPublicSettings (Read-Defensive) - Damit landet kein