CVE-2015-8010: XSS
Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga before 1.14 allows remote attackers to inject arbitrary web script or HTML via the query string to cgi-bin/status.cgi.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8010?
CVE-2015-8010 is classified as a high severity cross-site scripting (XSS) vulnerability.
How does CVE-2015-8010 affect Icinga?
CVE-2015-8010 allows remote attackers to inject arbitrary web scripts or HTML through the Classic-UI's CSV export link and pagination feature.
Which versions of Icinga are affected by CVE-2015-8010?
CVE-2015-8010 affects Icinga versions prior to 1.14, including all versions up to and including 1.13.4.
How do I fix CVE-2015-8010?
To fix CVE-2015-8010, upgrade your Icinga installation to version 1.14 or later.
Can CVE-2015-8010 be exploited through query strings?
Yes, CVE-2015-8010 can be exploited by injecting malicious scripts through the query string to cgi-bin/status.cgi.