PT-2017-7311 · Icinga+1 · Icinga+1

Ricardo

·

Publicado

2017-01-16

·

Atualizado

2018-11-05

·

CVE-2015-8010

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Icinga versions prior to 1.14
Description The issue is related to a cross-site scripting (XSS) vulnerability in the Classic-UI, specifically with the CSV export link and pagination feature. This allows remote attackers to inject arbitrary web script or HTML via the query string to the "cgi-bin/status.cgi" endpoint.
Recommendations For versions prior to 1.14, update to version 1.14 or later to resolve the issue.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-8010
OPENSUSE-SU-2017_0146-1
OPENSUSE-SU-2018_3258-1
SUSE-SU-2018:3620-1

Produtos afetados

Icinga
Suse