Nagios XI
cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*
- 2024R1.2.2
A stored cross-site scripting vulnerability has been identified in Nagios XI version 2024R1.2.2, specifically on the Tools page. This vulnerability allows an attacker to inject malicious scripts into the Tools interface, where they are stored and executed in the context of other users who access the page. Exploitation of this issue could result in unauthorized actions, session hijacking, or data theft.
Exploitation of this vulnerability could lead to session hijacking, allowing an attacker to impersonate a user, or execution of unauthorized actions on behalf of the user.
Users are advised to update to the latest version of Nagios XI.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.