Search CVE reports


Toggle filters

21 – 23 of 23 results


CVE-2018-18248

Medium priority
Needs evaluation

Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/timeline query string, or the /icingaweb2/setup query string.

1 affected package

icingaweb2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icingaweb2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2018-18247

Medium priority
Needs evaluation

Icinga Web 2 before 2.6.2 has XSS via the /icingaweb2/navigation/add icon parameter.

1 affected package

icingaweb2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icingaweb2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2018-18246

Medium priority
Needs evaluation

Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/moduleenable?name=setup to enable the setup module.

1 affected package

icingaweb2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icingaweb2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages