CVE-2013-10074: Nagios XI < 2012R2.6 XSS via Tools Menu
Nagios XI versions prior to 2012R2.6 are vulnerable to cross-site scripting (XSS) via the Tools Menu of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2013-10074?
CVE-2013-10074 is classified as a moderate severity vulnerability due to its potential for exploitation via cross-site scripting.
How do I fix CVE-2013-10074?
To fix CVE-2013-10074, you should upgrade Nagios XI to version 2012R2.6 or later.
What does CVE-2013-10074 exploit?
CVE-2013-10074 exploits insufficient validation or escaping of user-supplied input in the Tools Menu of the Nagios XI web interface.
Who is affected by CVE-2013-10074?
CVE-2013-10074 affects users of Nagios XI versions prior to 2012R2.6.
What kind of attack is associated with CVE-2013-10074?
CVE-2013-10074 is associated with cross-site scripting (XSS) attacks that can lead to arbitrary script execution in the victim's browser.