Medium severity6.1NVD Advisory· Published Mar 27, 2017· Updated Jun 17, 2026
CVE-2015-8010
CVE-2015-8010
Description
Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga before 1.14 allows remote attackers to inject arbitrary web script or HTML via the query string to cgi-bin/status.cgi.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- Range: <1.14
- osv-coords2 versionspkg:rpm/suse/icinga&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/icinga&distro=SUSE%20Manager%20Client%20Tools%2012
< 1.13.3-12.3.1+ 1 more
- (no CPE)range: < 1.13.3-12.3.1
- (no CPE)range: < 1.13.3-12.3.1
Patches
Vulnerability mechanics
References
5- github.com/Icinga/icinga-core/issues/1563nvdPatchThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2017-01/msg00019.htmlnvdThird Party Advisory
- www.openwall.com/lists/oss-security/2015/10/23/15nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2015/10/29/15nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/97145nvd
News mentions
0No linked articles in our index yet.