[Bug 1119785] VUL-1: CVE-2018-18247: icingaweb2: XSS via /icingaweb2/navigation/add