PT-2021-20062 · Nagios · Nagios Xi

Scott Tolley

·

Published

2021-10-14

·

Updated

2021-10-20

·

CVE-2021-33179

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 5.8.4
Description The general user interface is vulnerable to authenticated reflected cross-site scripting. An authenticated victim, who accesses a specially crafted malicious URL, would unknowingly execute the attached payload.
Recommendations For Nagios XI versions prior to 5.8.4, update to version 5.8.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the user interface to minimize the risk of exploitation. Avoid accessing suspicious or untrusted URLs while authenticated to the Nagios XI interface until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-33179

Affected Products

Nagios Xi