CVE-2018-10554: XSS
An issue was discovered in Nagios XI 5.4.13. There is XSS exploitable via CSRF in (1) the Schedule New Report screen via the hour, minute, or ampm parameter, related to components/scheduledreporting; (2) includes/components/xicore/downtime.php, related to the updatepages function; (3) the ajaxhelper.php opts or background parameter; (4) the i[] array parameter to ajaxhandler.php; or (5) the deploynotification.php title parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10554?
CVE-2018-10554 has been classified as a medium severity vulnerability due to its potential for cross-site scripting exploitation.
How do I fix CVE-2018-10554?
To fix CVE-2018-10554, users should upgrade Nagios XI to version 5.4.14 or later.
What type of attacks can CVE-2018-10554 facilitate?
CVE-2018-10554 allows for cross-site scripting (XSS) attacks via multiple entry points in the application.
Is CVE-2018-10554 present in other versions of Nagios XI?
CVE-2018-10554 specifically affects Nagios XI version 5.4.13 and may not be present in earlier or later versions.
What components of Nagios XI are impacted by CVE-2018-10554?
CVE-2018-10554 impacts the Schedule New Report screen and the downtime.php component within Nagios XI.