JavaScript Injection Vulnerability in Icinga Reporting by Icinga
CVE-2025-27406
7.7HIGH
What is CVE-2025-27406?
The Icinga Reporting component within the Icinga Web 2 framework has a vulnerability that permits users to create templates capable of embedding arbitrary JavaScript code. This flaw allows malicious actors to execute scripts in the context of the user when templates are previewed or within the headless browser when reports are generated in PDF format. This issue has been mitigated in version 1.0.3 of Icinga Reporting. Administrators are advised to audit existing templates and eliminate any suspicious configurations to safeguard against potential exploitation.
Affected Version(s)
icingaweb2-module-reporting >= 0.10.0, < 1.0.3
