First published: Mon Mar 27 2017(Updated: )
Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga before 1.14 allows remote attackers to inject arbitrary web script or HTML via the query string to cgi-bin/status.cgi.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Icinga Icinga Web 2 | <=1.13.4 | |
SUSE Linux | =42.2 | |
openSUSE Leap | =42.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8010 is classified as a high severity cross-site scripting (XSS) vulnerability.
CVE-2015-8010 allows remote attackers to inject arbitrary web scripts or HTML through the Classic-UI's CSV export link and pagination feature.
CVE-2015-8010 affects Icinga versions prior to 1.14, including all versions up to and including 1.13.4.
To fix CVE-2015-8010, upgrade your Icinga installation to version 1.14 or later.
Yes, CVE-2015-8010 can be exploited by injecting malicious scripts through the query string to cgi-bin/status.cgi.