Nagios XI Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in Nagios XI version 2024R1.2.2, specifically on the Tools page. This vulnerability allows an attacker to inject malicious scripts into the Tools interface, where they are stored and executed in the context of other users who access the page. Exploitation of this issue could result in unauthorized actions, session hijacking, or data theft.

Impact

Exploitation of this vulnerability could lead to session hijacking, allowing an attacker to impersonate a user, or execution of unauthorized actions on behalf of the user.

Remediation

Users are advised to update to the latest version of Nagios XI.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
1.7
exploitability
5.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.