PT-2025-2637 · Nagios Xi · Nagios Xi

Published

2025-01-09

·

Updated

2025-01-10

·

CVE-2024-42898

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nagios XI version 2024R1.1.4
Description A cross-site scripting (XSS) issue allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Account Settings page. This enables attackers to potentially manipulate user sessions or steal sensitive information.
Recommendations For Nagios XI version 2024R1.1.4, as a temporary workaround, consider restricting access to the Account Settings page until a patch is available. Avoid using the Name parameter in the affected page to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-42898

Affected Products

Nagios Xi