AI Score
Confidence
High
EPSS
Percentile
30.9%
Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/moduleenable?name=setup to enable the setup module.
lists.opensuse.org/opensuse-security-announce/2020-01/msg00031.html
herolab.usd.de/wp-content/uploads/sites/4/2018/12/usd20180027.txt