PT-2025-44476 · Nagios Enterprises · Nagios Xi+1

Published

2025-10-30

·

Updated

2025-10-30

·

CVE-2021-47692

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to CCM 3.1.2 Nagios XI versions prior to 5.8.4
Description The Core Config Manager (CCM) in Nagios XI is susceptible to a cross-site scripting (XSS) issue through the lock page functionality. A lack of proper input validation or escaping could allow an attacker to inject and execute arbitrary scripts within a user's browser.
Recommendations Update to CCM version 3.1.2 or later. Update to Nagios XI version 5.8.4 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-47692

Affected Products

Core Config Manager
Nagios Xi