PT-2025-44478 · Nagios Enterprises · Nagios Xi+1

Amit Raut

·

Published

2025-10-30

·

Updated

2025-10-30

·

CVE-2021-47694

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to CCM 3.1.4 Nagios XI versions prior to 5.8.6
Description The Core Config Manager (CCM) in Nagios XI is subject to a reflected cross-site scripting (XSS) issue through the Test Command functionality. A lack of proper input validation or escaping could allow an attacker to inject and execute arbitrary script within a user's browser.
Recommendations Update to CCM version 3.1.4 or later. Update to Nagios XI version 5.8.6 or later.

Fix

Improper Encoding or Escaping of Output

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-47694

Affected Products

Core Config Manager
Nagios Xi