VDB
Sign up
HIGH7.6

GHSA-55wf-5m3q-6jjf

ipl/web is vulnerable to reflected XSS by malformed search requests

Quick fix

GHSA-55wf-5m3q-6jjf — ipl/web: upgrade to the fixed version with the command below.

composer require ipl/web:^0.13.1

Details

### Impact The vulnerability allows an attacker to inject malicious Javascript into a victim's browser to run it in the context of Icinga Web. The victim needs to visit a specifically prepared website and may have no immediate chance to notice any wrongdoing.

### Patches Version 0.13.1 includes a fix for this. It will be published as part of `icinga-php-library` version 0.19.2.

### Workarounds Enable the Content-Security-Policy (CSP) in the general configuration of Icinga Web available since version 2.12.0.

### References None

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/ipl/web
Introduced in: 0.11.0Fixed in: 0.13.1
Fixcomposer require ipl/web:^0.13.1
Packagist/ipl/web
Introduced in: 0Fixed in: 0.10.3
Fixcomposer require ipl/web:^0.10.3

References