Icinga Reporting is the central component for reporting related functionality in the monitoring web frontend and framework Icinga Web 2. A vulnerability present in versions 0.10.0 through 1.0.2 allows to set up a template that allows to embed arbitrary Javascript. This enables the attacker to act on behalf of the user, if the template is being previewed; and act on behalf of the headless browser, if a report using the template is printed to PDF. This issue has been resolved in version 1.0.3 of Icinga Reporting. As a workaround, review all templates and remove suspicious settings.
Metrics
Affected Vendors & Products
References
History
Wed, 26 Mar 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 26 Mar 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Icinga Reporting is the central component for reporting related functionality in the monitoring web frontend and framework Icinga Web 2. A vulnerability present in versions 0.10.0 through 1.0.2 allows to set up a template that allows to embed arbitrary Javascript. This enables the attacker to act on behalf of the user, if the template is being previewed; and act on behalf of the headless browser, if a report using the template is printed to PDF. This issue has been resolved in version 1.0.3 of Icinga Reporting. As a workaround, review all templates and remove suspicious settings. | |
Title | Icinga Reporting Stored XSS leads to SSRF | |
Weaknesses | CWE-79 CWE-918 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-03-26T15:49:45.273Z
Updated: 2025-03-26T16:15:22.593Z
Reserved: 2025-02-24T15:51:17.267Z
Link: CVE-2025-27406

Updated: 2025-03-26T16:15:19.109Z

Status : Received
Published: 2025-03-26T16:15:23.147
Modified: 2025-03-26T16:15:23.147
Link: CVE-2025-27406

No data.