PT-2025-44530 · Nagios Enterprises · Nagios Xi

Published

2025-10-30

·

Updated

2025-10-30

·

CVE-2011-10039

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 2011R1.9
Description Nagios XI versions prior to 2011R1.9 are susceptible to cross-site scripting (XSS). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser through the Alert Heatmap report and the “My Reports” listing of the web interface.
Recommendations Update Nagios XI to version 2011R1.9 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2011-10039

Affected Products

Nagios Xi