Description
Inciga Web 2.8.2 contains a client-side cross-site scripting vulnerability that allows remote attackers to inject malicious script codes through the icinga.min.js file. Attackers can exploit the EventListener.handleEvent method to execute arbitrary scripts, potentially leading to session hijacking and non-persistent phishing attacks.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
2.8.2
Credits
Vulnerability-Lab [Research Team]
References
www.vulnerability-lab.com/get_content.php?id=2273 (Vulnerability Lab Advisory)
icinga.com/ (Product Homepage)
github.com/Icinga/icingaweb2 (Product Homepage)
www.vulncheck.com/...-cross-site-scripting-via-eventlistener (VulnCheck Advisory: Inciga Web 2.8.2 Client-Side Cross-Site Scripting via EventListener)