ipl/web is a set of common web components for php projects. Prior to versions 0.13.1 and 0.10.3, the vulnerability allows an attacker to inject malicious Javascript into a victim's browser to run it in the context of Icinga Web. The victim needs to visit a specifically prepared website and may have no immediate chance to notice any wrongdoing. This issue has been patched in versions 0.13.1 and 0.10.3.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-05-08 23:16
Updated : 2026-06-17 10:47
NVD link : CVE-2026-42224
Mitre link : CVE-2026-42224
CVE.ORG link : CVE-2026-42224
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
