CVE-2026-42224 Details
Description
ipl/web is a set of common web components for php projects. Prior to versions 0.13.1 and 0.10.3, the vulnerability allows an attacker to inject malicious Javascript into a victim's browser to run it in the context of Icinga Web. The victim needs to visit a specifically prepared website and may have no immediate chance to notice any wrongdoing. This issue has been patched in versions 0.13.1 and 0.10.3.
A reflected cross-site scripting vulnerability has been identified in Icinga ipl-web versions prior to 0.13.1. This issue allows an attacker to inject malicious JavaScript that is executed in the context of the Icinga Web application. The exploitation requires the victim to visit a specially crafted website, and the injected script may go unnoticed immediately.
Users can upgrade to Icinga ipl-web version 0.13.1, which addresses this vulnerability. This version will also be included in the upcoming Icinga PHP Library release 0.19.2. Alternatively, Icinga Web users can enable the Content-Security-Policy (CSP) in their general configuration, a feature available since Icinga Web version 2.12.0.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 8, 2026CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Icinga ipl-web | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 9, 2026 | CVE Modified | [email protected] |
| May 8, 2026 | New CVE Received | [email protected] |
Volerion