PT-2025-44473 · Nagios Enterprises · Nagios Xi+1

Matthew Aberegg

·

Published

2025-10-30

·

Updated

2025-10-30

·

CVE-2021-47689

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to CCM 3.1.0 Nagios XI versions prior to 5.8.0
Description The Core Config Manager (CCM) in Nagios XI contains a cross-site scripting (XSS) issue in the Templates pages. The problem is related to the UI logic that renders and handles the Active/Actions buttons. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
Recommendations Update to CCM version 3.1.0 or later. Update to Nagios XI version 5.8.0 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-47689

Affected Products

Core Config Manager
Nagios Xi