First published: Wed Jun 19 2019(Updated: )
A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript code within the auto login admin management page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios | <5.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17146 is classified as a medium severity cross-site scripting vulnerability.
To mitigate CVE-2018-17146, upgrade Nagios XI to version 5.5.4 or later.
CVE-2018-17146 affects Nagios XI versions prior to 5.5.4.
Exploitation of CVE-2018-17146 allows attackers to execute arbitrary JavaScript code.
The vulnerability in CVE-2018-17146 is found in the 'name' parameter on the Account Information page.