First published: Wed Nov 14 2018(Updated: )
Nagios XI 5.5.6 allows persistent cross site scripting from remote authenticated attackers via the stored email address in admin/users.php.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios | =5.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15713 has a medium severity rating due to its potential for persistent cross-site scripting attacks.
To fix CVE-2018-15713, upgrade to a newer version of Nagios XI that resolves this vulnerability.
CVE-2018-15713 specifically affects Nagios XI version 5.5.6.
CVE-2018-15713 allows authenticated attackers to execute malicious scripts through stored email addresses.
Yes, CVE-2018-15713 can be exploited by remote authenticated attackers.