PT-2025-44466 · Nagios Enterprises · Nagios Xi+1

·

CVE-2020-36860

·

Published

2025-10-30

·

Updated

2025-10-30

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to CCM 3.0.7 Nagios XI versions prior to 5.7.4
Description The Core Config Manager (CCM) in Nagios XI is susceptible to multiple cross-site scripting (XSS) issues present in the object edit pages. Insufficient validation or escaping of user-supplied input could allow an attacker to inject and execute arbitrary script within a victim’s browser.
Recommendations Update to CCM version 3.0.7 or later. Update to Nagios XI version 5.7.4 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36860

Affected Products

Core Config Manager
Nagios Xi