CVE-2025-27404
CVSS 3.1 Score 7.6 of 10 (high)
Details
Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 79
Summary
CVE-2025-27404 is a vulnerability affecting Icinga Web 2, an open-source monitoring interface, framework, and command-line tool. This issue, present in versions prior to 2.11.5 and 2.12.13, enables an attacker to inject arbitrary JavaScript into the platform by crafting malicious URLs. Once visited by any user, the attacker can act on behalf of that user. The vulnerability has been addressed in versions 2.11.5 and 2.12.3. As a temporary measure, users of Icinga Web 2.12.2 can enable a content security policy in the application settings.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Icinga Web 2