Icinga Web 2 DOM-Based Cross-Site Scripting Vulnerability

Vulnerability

A DOM-based cross-site scripting vulnerability has been identified in Icinga Web 2 versions prior to 2.12.2. This issue allows an attacker to create a URL that, when visited by a user, embeds arbitrary JavaScript into the application and acts on behalf of that user. The vulnerability arises from insufficient input sanitization, enabling the injection of malicious scripts that can be executed in the context of the user's session.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where injected JavaScript is executed in the context of the user, potentially leading to session hijacking or other malicious actions.

Remediation

Users can upgrade to Icinga Web 2.11.5 or 2.12.3 to address this vulnerability. Those on version 2.12.2 can enable a content security policy in the application settings as a temporary workaround.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
1.7
exploitability
4.6
remediation
8.3
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.