PT-2025-44475 · Nagios Enterprises · Nagios Xi+1

Published

2025-10-30

·

Updated

2025-10-30

·

CVE-2021-47691

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 5.8.2 Core Config Manager (CCM) versions prior to 3.1.1
Description The Core Config Manager (CCM) in Nagios XI is susceptible to cross-site scripting (XSS) issues through the Services page. The config name and service description fields lack proper input validation or escaping, potentially enabling an attacker to inject and execute arbitrary scripts within a user's browser.
Recommendations Update Nagios XI to version 5.8.2 or later. Update Core Config Manager (CCM) to version 3.1.1 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-47691

Affected Products

Core Config Manager
Nagios Xi