GHSA-55wf-5m3q-6jjfHighCVSS 7.6
ipl/web is vulnerable to reflected XSS by malformed search requests
🔗 CVE IDs covered (1)
📋 Description
Impact
The vulnerability allows an attacker to inject malicious Javascript into a victim's browser to run it in the context of Icinga Web. The victim needs to visit a specifically prepared website and may have no immediate chance to notice any wrongdoing.
Patches
Version 0.13.1 includes a fix for this. It will be published as part of icinga-php-library version 0.19.2.
Workarounds
Enable the Content-Security-Policy (CSP) in the general configuration of Icinga Web available since version 2.12.0.
References
None
🎯 Affected products2
- composer/ipl/web:>= 0.11.0, <= 0.13.0
- composer/ipl/web:<= 0.10.2
🔗 References (6)
- https://github.com/Icinga/ipl-web/security/advisories/GHSA-55wf-5m3q-6jjf
- https://github.com/Icinga/ipl-web/commit/f387e92504d7a03bb857d1aee9b7410e06dd065d
- https://github.com/Icinga/ipl-web/releases/tag/v0.13.1
- https://nvd.nist.gov/vuln/detail/CVE-2026-42224
- https://github.com/Icinga/ipl-web/releases/tag/v0.10.3
- https://github.com/advisories/GHSA-55wf-5m3q-6jjf