[Bug 1119801] VUL-1: CVE-2018-18248: icingaweb2: an XSS attack is possible via query strings or a dir parameter