Icinga Web 2
cpe:2.3:a:icinga:icinga_web_2:*:*:*:*:*:*:*
- <= 2.12.2
A DOM-based cross-site scripting vulnerability has been identified in Icinga Web 2 versions prior to 2.12.2. This issue allows an attacker to create a URL that, when visited by a user, embeds arbitrary JavaScript into the application and acts on behalf of that user. The vulnerability arises from insufficient input sanitization, enabling the injection of malicious scripts that can be executed in the context of the user's session.
Exploitation of this vulnerability allows for cross-site scripting, where injected JavaScript is executed in the context of the user, potentially leading to session hijacking or other malicious actions.
Users can upgrade to Icinga Web 2.11.5 or 2.12.3 to address this vulnerability. Those on version 2.12.2 can enable a content security policy in the application settings as a temporary workaround.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.