First published: Mon Dec 17 2018(Updated: )
Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/timeline query string, or the /icingaweb2/setup query string.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Icinga Icinga Web 2 | =2.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2018-18248.
The affected software is Icinga Web 2 version 2.6.1.
The severity of CVE-2018-18248 is medium with a CVSS score of 6.1.
CVE-2018-18248 occurs through cross-site scripting (XSS) vulnerabilities in various parameters of Icinga Web 2.
Yes, there are fixes available for CVE-2018-18248. It is recommended to update to a patched version of Icinga Web 2.