PT-2025-44486 · Nagios Enterprises · Nagios Xi

Aleksey Solovev

·

Published

2025-10-30

·

Updated

2025-10-30

·

CVE-2023-53688

CVSS v3.1
5.4
VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 5.11.3
Description The software is susceptible to cross-site scripting (XSS) and cross-site request forgery (CSRF) through the Hypermap Replay component. An attacker can submit crafted input that is not properly validated or escaped, leading to the injection of malicious script that executes within a victim’s browser (XSS). The component also lacks sufficient anti-CSRF protections on operations that change system state, potentially allowing an attacker to make authenticated users perform unintended actions.
Recommendations Update to version 5.11.3 or later.

Fix

CSRF

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-14533
CVE-2023-53688

Affected Products

Nagios Xi