PT-2025-44487 · Nagios · Nagios Fusion

Tisha Manandhar

·

Published

2025-10-30

·

Updated

2025-10-30

·

CVE-2023-53689

CVSS v2.0
8.5
VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Nagios Fusion versions prior to 4.2.0
Description Nagios Fusion versions prior to 4.2.0 have a reflected cross-site scripting (XSS) issue in the license key configuration process. This allows an attacker to execute scripts in a user's browser by tricking them into following a specially crafted URL. Successful exploitation can lead to the theft of credentials or session information, potentially granting unauthorized administrative access.
Recommendations Update to Nagios Fusion version 4.2.0 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-15969
CVE-2023-53689

Affected Products

Nagios Fusion