PT-2025-44467 · Nagios Enterprises · Nagios Xi+1

Published

2025-10-30

·

Updated

2025-10-30

·

CVE-2020-36861

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 5.7.5 Core Config Manager (CCM) versions prior to 3.0.8
Description The Core Config Manager (CCM) in Nagios XI has multiple cross-site scripting (XSS) issues in the overlay UI elements and the Notification/Check Period pages. Insufficient validation or escaping of user-supplied input could allow an attacker to inject and execute arbitrary script in a victim’s browser.
Recommendations Update Nagios XI to version 5.7.5 or later. Update Core Config Manager (CCM) to version 3.0.8 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-36861

Affected Products

Core Config Manager
Nagios Xi