CVE-2015-8010
Description
XSS in Icinga Classic-UI CSV export and pagination via unsanitized QUERY_STRING allows remote attackers to inject arbitrary script or HTML.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
XSS in Icinga Classic-UI CSV export and pagination via unsanitized QUERY_STRING allows remote attackers to inject arbitrary script or HTML.
Vulnerability
A cross-site scripting (XSS) vulnerability exists in the Classic-UI component of Icinga before version 1.14. The bug resides in the CSV export link and pagination feature, where the function parsing the QUERY_STRING environment variable does not properly sanitize input before reflecting it in the HTML output. This allows an attacker to inject arbitrary web script or HTML via the query string to /cgi-bin/status.cgi [1][2]. The vulnerability was introduced in version 1.3 and affects all versions up to 1.13.3 [2][3].
Exploitation
An attacker can exploit this vulnerability by crafting a malicious URL with a query string containing XSS payload. For example: http://classic.demo.icinga.org/icinga/cgi-bin/status.cgi?host=all&'onmouseover='prompt(25435);'bad=' [2]. No authentication or special privileges are required; the attacker only needs to lure a victim into clicking the crafted link or visiting a page that triggers the vulnerable functionality [1][2].
Impact
Successful exploitation results in arbitrary JavaScript execution in the context of the victim's browser session. This can lead to information disclosure, session hijacking, defacement, or other actions that the authenticated user can perform. The impact is limited to the Classic-UI interface and depends on the privileges of the targeted user [2][3].
Mitigation
The vulnerability is fixed in Icinga version 1.14, released on or around 2015-10-30 [3]. The fix sanitizes the QUERY_STRING parsing by reworking the getcgivars() function so that parsed CGI parameters are properly handled and output encoding is applied [3]. Users should upgrade to Icinga 1.14 or later. No workaround is provided for older versions; if upgrading is not possible, restrict access to the Classic-UI and avoid using untrusted query strings [1][3].
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
6- osv-coords2 versionspkg:rpm/suse/icinga&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/icinga&distro=SUSE%20Manager%20Client%20Tools%2012
< 1.13.3-12.3.1+ 1 more
- (no CPE)range: < 1.13.3-12.3.1
- (no CPE)range: < 1.13.3-12.3.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/Icinga/icinga-core/issues/1563nvdPatchThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2017-01/msg00019.htmlnvdThird Party Advisory
- www.openwall.com/lists/oss-security/2015/10/23/15nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2015/10/29/15nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/97145nvd
News mentions
0No linked articles in our index yet.