vendor:
Nagios XI
by:
Matthew Aberegg
8.8
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: Nagios XI
Affected Version From: Nagios XI 5.7.5
Affected Version To: Nagios XI 5.7.5
Patch Exists: YES
Related CWE: N/A
CPE: a:nagios:nagios_xi
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04
2021
Nagios XI 5.7.5 – Multiple Persistent Cross-Site Scripting
A persistent cross-site scripting vulnerability exists in the 'My Tools' and 'Business Process Intelligence' functionalities of Nagios XI. The vulnerable parameters are 'url' and 'groupID' respectively. An attacker can create a tool or BPI group with an XSS payload and click on the URL link or Group ID to trigger the payload.
Mitigation:
The user should update to the latest version of Nagios XI to mitigate this vulnerability.