vendor:
Nagios XI
by:
Unknown
5.5
CVSS
MEDIUM
Cross-site request-forgery
352
CWE
Product Name: Nagios XI
Affected Version From: 2009R1.2B
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: a:nagios:nagios_xi:2009r1.2b
Platforms Tested:
Unknown
Cross-site request-forgery vulnerabilities in Nagios XI
Nagios XI is prone to multiple cross-site request-forgery vulnerabilities because the application fails to properly validate HTTP requests. Successful exploit requires that the 'nagiosadmin' be logged into the web interface. Attackers can exploit these issues to gain unauthorized access to the affected application and perform certain administrative actions.
Mitigation:
Unknown