CVE Explorer
CVE-2026-42224
ipl/web is a set of common web components for php projects. Prior to versions 0.13.1 and 0.10.3, the vulnerability allows an attacker to inject malicious Javascript into a victim's browser to run it in the context of Icinga Web. The victim needs to visit a specifically prepared website and may have no immediate chance to notice any wrongdoing. This issue has been patched in versions 0.13.1 and 0.10.3.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"ipl-web","vendor":"Icinga","versions":[{"status":"affected","version":">= 0.11.0, < 0.13.1"},{"status":"affected","version":"< 0.10.3"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:7c22a6545a2dd6cbc60c896ebf15c83d0b4aedf2127242103da23d112b668694 · sha256:273e44aee7930e5f… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.6,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:7c22a6545a2dd6cbc60c896ebf15c83d0b4aedf2127242103da23d112b668694 · sha256:273e44aee7930e5f… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-79","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7c22a6545a2dd6cbc60c896ebf15c83d0b4aedf2127242103da23d112b668694 · sha256:273e44aee7930e5f… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/Icinga/ipl-web/commit/f387e92504d7a03bb857d1aee9b7410e06dd065d","tags":["x_refsource_MISC"],"url":"https://github.com/Icinga/ipl-web/commit/f387e92504d7a03bb857d1aee9b7410e06dd065d"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7c22a6545a2dd6cbc60c896ebf15c83d0b4aedf2127242103da23d112b668694 · sha256:273e44aee7930e5f… · /containers/cna/references/1
{"name":"https://github.com/Icinga/ipl-web/releases/tag/v0.10.3","tags":["x_refsource_MISC"],"url":"https://github.com/Icinga/ipl-web/releases/tag/v0.10.3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7c22a6545a2dd6cbc60c896ebf15c83d0b4aedf2127242103da23d112b668694 · sha256:273e44aee7930e5f… · /containers/cna/references/2
{"name":"https://github.com/Icinga/ipl-web/releases/tag/v0.13.1","tags":["x_refsource_MISC"],"url":"https://github.com/Icinga/ipl-web/releases/tag/v0.13.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7c22a6545a2dd6cbc60c896ebf15c83d0b4aedf2127242103da23d112b668694 · sha256:273e44aee7930e5f… · /containers/cna/references/3
{"name":"https://github.com/Icinga/ipl-web/security/advisories/GHSA-55wf-5m3q-6jjf","tags":["x_refsource_CONFIRM"],"url":"https://github.com/Icinga/ipl-web/security/advisories/GHSA-55wf-5m3q-6jjf"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7c22a6545a2dd6cbc60c896ebf15c83d0b4aedf2127242103da23d112b668694 · sha256:273e44aee7930e5f… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.