Nagios XI
cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*
- < 2024R1.1.2
A reflected cross-site scripting vulnerability has been identified in Nagios XI versions prior to 2024R1.1.2. This issue arises on the login page when accessed with older web browsers. The vulnerability is due to insufficient validation or escaping of user-supplied input, which is reflected by the login page. An attacker can craft a malicious link that, when clicked by a victim, executes arbitrary JavaScript in the victim's browser within the context of the Nagios XI site. While this issue is prominent in legacy browsers, modern browsers may mitigate some of the attack vectors.
Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
To reproduce this vulnerability, access the Nagios XI login page using an older web browser that does not have modern security features. Once on the login page, inject a script through a crafted link that exploits the lack of input validation. This can be done by manipulating the URL to include JavaScript code, which will be executed when the link is followed.
Users can upgrade to Nagios XI version 2024R1.1.2 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.