CVE-2018-18248: XSS
Published Dec 17, 2018
·Updated
Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/timeline query string, or the /icingaweb2/setup query string.
Affected Software
1 affected component
Icinga Icinga Web 2=2.6.1
Event History
Dec 17, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2018-18248.
2
What is the affected software?
The affected software is Icinga Web 2 version 2.6.1.
3
What is the severity of CVE-2018-18248?
The severity of CVE-2018-18248 is medium with a CVSS score of 6.1.
4
How does CVE-2018-18248 occur?
CVE-2018-18248 occurs through cross-site scripting (XSS) vulnerabilities in various parameters of Icinga Web 2.
5
Are there any available fixes for CVE-2018-18248?
Yes, there are fixes available for CVE-2018-18248. It is recommended to update to a patched version of Icinga Web 2.