Icinga Web 2 before 2.6.2 has XSS via the /icingaweb2/navigation/add icon parameter.
{
"binaries": [
{
"binary_version": "2.4.1-1ubuntu0.1",
"binary_name": "icingacli"
},
{
"binary_version": "2.4.1-1ubuntu0.1",
"binary_name": "icingaweb2"
},
{
"binary_version": "2.4.1-1ubuntu0.1",
"binary_name": "icingaweb2-common"
},
{
"binary_version": "2.4.1-1ubuntu0.1",
"binary_name": "icingaweb2-module-monitoring"
},
{
"binary_version": "2.4.1-1ubuntu0.1",
"binary_name": "php-icinga"
}
]
}{
"binaries": [
{
"binary_version": "2.7.3-1",
"binary_name": "icingacli"
},
{
"binary_version": "2.7.3-1",
"binary_name": "icingaweb2"
},
{
"binary_version": "2.7.3-1",
"binary_name": "icingaweb2-common"
},
{
"binary_version": "2.7.3-1",
"binary_name": "icingaweb2-module-monitoring"
},
{
"binary_version": "2.7.3-1",
"binary_name": "php-icinga"
}
]
}{
"binaries": [
{
"binary_version": "2.9.5-1",
"binary_name": "icingacli"
},
{
"binary_version": "2.9.5-1",
"binary_name": "icingaweb2"
},
{
"binary_version": "2.9.5-1",
"binary_name": "icingaweb2-common"
},
{
"binary_version": "2.9.5-1",
"binary_name": "icingaweb2-module-monitoring"
},
{
"binary_version": "2.9.5-1",
"binary_name": "php-icinga"
}
]
}{
"binaries": [
{
"binary_version": "2.12.1-1",
"binary_name": "icingacli"
},
{
"binary_version": "2.12.1-1",
"binary_name": "icingaweb2"
},
{
"binary_version": "2.12.1-1",
"binary_name": "icingaweb2-common"
},
{
"binary_version": "2.12.1-1",
"binary_name": "icingaweb2-module-monitoring"
},
{
"binary_version": "2.12.1-1",
"binary_name": "php-icinga"
}
]
}{
"binaries": [
{
"binary_version": "2.12.4-2",
"binary_name": "icingacli"
},
{
"binary_version": "2.12.4-2",
"binary_name": "icingaweb2"
},
{
"binary_version": "2.12.4-2",
"binary_name": "icingaweb2-common"
},
{
"binary_version": "2.12.4-2",
"binary_name": "icingaweb2-module-monitoring"
},
{
"binary_version": "2.12.4-2",
"binary_name": "php-icinga"
}
]
}