HarborGuard / CVE
Back to search
HIGHCVE-2026-42224Published Modified CNA GitHub_M

CVE-2026-42224: ipl/web is vulnerable to reflected XSS by malformed search requests

ipl/web is a set of common web components for php projects. Prior to version 0.13.1, the vulnerability allows an attacker to inject malicious Javascript into a victim's browser to run it in the context of Icinga Web. The victim needs to visit a specifically prepared website and may have no immediate chance to notice any wrongdoing. This issue has been patched in version 0.13.1.

Metrics

CVSS v3.1
7.6
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • Icinga / ipl-web
    < 0.13.1
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
CVE-2026-42224: ipl/web is vulnerable to reflected XSS by malformed search requests | HarborGuard CVE