CVE-2015-3618: XSS
Published Feb 6, 2018
·Updated
Cross-site scripting (XSS) vulnerability in Nagios Business Process Intelligence (BPI) before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via vectors involving index.php.
Affected Software
1 affected component
Nagios Business Process Intelligence<2.3.4
Event History
Feb 6, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3618?
CVE-2015-3618 has a high severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2015-3618?
To fix CVE-2015-3618, upgrade Nagios Business Process Intelligence to version 2.3.4 or later.
3
What types of attacks can CVE-2015-3618 enable?
CVE-2015-3618 can enable remote attackers to perform cross-site scripting (XSS) attacks.
4
Which versions of Nagios Business Process Intelligence are affected by CVE-2015-3618?
CVE-2015-3618 affects Nagios Business Process Intelligence versions prior to 2.3.4.
5
Where can I find more information about CVE-2015-3618?
Information about CVE-2015-3618 can be found in the Nagios changelog and various security vulnerability databases.