ipl/web is vulnerable to reflected XSS by malformed search requests
Package
Affected versions
>= 0.11.0, <= 0.13.0
<= 0.10.2
Patched versions
0.13.1
0.10.3
Description
Published to the GitHub Advisory Database
Apr 29, 2026
Reviewed
Apr 29, 2026
Published by the National Vulnerability Database
May 8, 2026
Last updated
Jun 9, 2026
Impact
The vulnerability allows an attacker to inject malicious Javascript into a victim's browser to run it in the context of Icinga Web. The victim needs to visit a specifically prepared website and may have no immediate chance to notice any wrongdoing.
Patches
Version 0.13.1 includes a fix for this. It will be published as part of
icinga-php-libraryversion 0.19.2.Workarounds
Enable the Content-Security-Policy (CSP) in the general configuration of Icinga Web available since version 2.12.0.
References
None
References