Impact
The vulnerability allows to set up a template that allows to embed arbitrary Javascript.
This enables the attacker to
- act on behalf of the user, if the template is being previewed
- act on behalf of the headless browser, if a report using the template is printed to PDF
Patches
This issue has been resolved in version 1.0.3 of Icinga Reporting.
Workarounds
Review all templates and remove suspicious settings.
Impact
The vulnerability allows to set up a template that allows to embed arbitrary Javascript.
This enables the attacker to
Patches
This issue has been resolved in version 1.0.3 of Icinga Reporting.
Workarounds
Review all templates and remove suspicious settings.