Security Advisory

CVE-2018-18248

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-12-17 15:00:00
Last updated 2024-08-05 11:01:14
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/timeline query string, or the /icingaweb2/setup query string.