GHSA-55wf-5m3q-6jjfHighCVSS 7.6

ipl/web is vulnerable to reflected XSS by malformed search requests

Published
April 29, 2026
Last Modified
June 9, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

The vulnerability allows an attacker to inject malicious Javascript into a victim's browser to run it in the context of Icinga Web. The victim needs to visit a specifically prepared website and may have no immediate chance to notice any wrongdoing.

Patches

Version 0.13.1 includes a fix for this. It will be published as part of icinga-php-library version 0.19.2.

Workarounds

Enable the Content-Security-Policy (CSP) in the general configuration of Icinga Web available since version 2.12.0.

References

None

🎯 Affected products2

  • composer/ipl/web:>= 0.11.0, <= 0.13.0
  • composer/ipl/web:<= 0.10.2

🔗 References (6)