PT-2018-14377 · Nagios+1 · Nagios Core+1

Maximilian Boehner

·

Published

2018-12-17

·

Updated

2024-06-15

·

CVE-2018-18245

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nagios Core version 4.4.2
Description The issue concerns an XSS flaw in the alert summary reports of plugin results. This can be demonstrated by a SCRIPT element delivered by a modified check load plugin to NRPE, allowing for potential exploitation.
Recommendations For Nagios Core version 4.4.2, update to a version that includes a fix for this issue to prevent XSS attacks.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-18245
DLA-1615-1
MGASA-2019-0104
OPENSUSE-SU-2020:0500-1
OPENSUSE-SU-2020:0517-1
OPENSUSE-SU-2020_0500-1
OPENSUSE-SU-2024:11073-1

Affected Products

Nagios Core
Suse