CVE-2016-15051: Nagios XI < 5.2.4 XSS via Report startdate/enddate Fields
Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the Reports interface through values from the startdate and enddate fields. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2016-15051?
CVE-2016-15051 is classified as a medium severity vulnerability due to the potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2016-15051?
To fix CVE-2016-15051, upgrade Nagios XI to version 5.2.4 or later.
What components are affected by CVE-2016-15051?
CVE-2016-15051 affects Nagios XI versions prior to 5.2.4 within its Reports interface.
What type of vulnerability is CVE-2016-15051?
CVE-2016-15051 is a cross-site scripting (XSS) vulnerability that allows injection of arbitrary scripts.
What can an attacker do with CVE-2016-15051?
An attacker can exploit CVE-2016-15051 to execute malicious scripts in the context of a user's session.