CVE-2025-27404

CVSS 3.1 Score 7.6 of 10 (high)

Details

Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 79

Summary

CVE-2025-27404 is a vulnerability affecting Icinga Web 2, an open-source monitoring interface, framework, and command-line tool. This issue, present in versions prior to 2.11.5 and 2.12.13, enables an attacker to inject arbitrary JavaScript into the platform by crafting malicious URLs. Once visited by any user, the attacker can act on behalf of that user. The vulnerability has been addressed in versions 2.11.5 and 2.12.3. As a temporary measure, users of Icinga Web 2.12.2 can enable a content security policy in the application settings.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share