CVE-2026-42224

ipl/web is a set of common web components for php projects. Prior to versions 0.13.1 and 0.10.3, the vulnerability allows an attacker to inject malicious Javascript into a victim's browser to run it in the context of Icinga Web. The victim needs to visit a specifically prepared website and may have no immediate chance to notice any wrongdoing. This issue has been patched in versions 0.13.1 and 0.10.3.
Configurations

No configuration.

History

No history.

Information

Published : 2026-05-08 23:16

Updated : 2026-06-17 10:47


NVD link : CVE-2026-42224

Mitre link : CVE-2026-42224

CVE.ORG link : CVE-2026-42224


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')