Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/moduleenable?name=setup to enable the setup module.
{ "binaries": [ { "binary_name": "icingacli", "binary_version": "2.9.5-1" }, { "binary_name": "icingaweb2", "binary_version": "2.9.5-1" }, { "binary_name": "icingaweb2-common", "binary_version": "2.9.5-1" }, { "binary_name": "icingaweb2-module-monitoring", "binary_version": "2.9.5-1" }, { "binary_name": "php-icinga", "binary_version": "2.9.5-1" } ] }
{ "binaries": [ { "binary_name": "icingacli", "binary_version": "2.12.1-1" }, { "binary_name": "icingaweb2", "binary_version": "2.12.1-1" }, { "binary_name": "icingaweb2-common", "binary_version": "2.12.1-1" }, { "binary_name": "icingaweb2-module-monitoring", "binary_version": "2.12.1-1" }, { "binary_name": "php-icinga", "binary_version": "2.12.1-1" } ] }
{ "binaries": [ { "binary_name": "icingacli", "binary_version": "2.12.2-1" }, { "binary_name": "icingaweb2", "binary_version": "2.12.2-1" }, { "binary_name": "icingaweb2-common", "binary_version": "2.12.2-1" }, { "binary_name": "icingaweb2-module-monitoring", "binary_version": "2.12.2-1" }, { "binary_name": "php-icinga", "binary_version": "2.12.2-1" } ] }
{ "binaries": [ { "binary_name": "icingacli", "binary_version": "2.4.1-1ubuntu0.1" }, { "binary_name": "icingaweb2", "binary_version": "2.4.1-1ubuntu0.1" }, { "binary_name": "icingaweb2-common", "binary_version": "2.4.1-1ubuntu0.1" }, { "binary_name": "icingaweb2-module-monitoring", "binary_version": "2.4.1-1ubuntu0.1" }, { "binary_name": "php-icinga", "binary_version": "2.4.1-1ubuntu0.1" } ] }
{ "binaries": [ { "binary_name": "icingacli", "binary_version": "2.7.3-1" }, { "binary_name": "icingaweb2", "binary_version": "2.7.3-1" }, { "binary_name": "icingaweb2-common", "binary_version": "2.7.3-1" }, { "binary_name": "icingaweb2-module-monitoring", "binary_version": "2.7.3-1" }, { "binary_name": "php-icinga", "binary_version": "2.7.3-1" } ] }