First published: Mon Dec 17 2018(Updated: )
An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php is not filtered, resulting in an XSS vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios | <5.5.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20171 is classified as a medium-severity vulnerability due to its potential for exploitation through cross-site scripting (XSS).
To fix CVE-2018-20171, upgrade Nagios XI to version 5.5.8 or later to ensure the vulnerability is patched.
CVE-2018-20171 exploits an unfiltered url parameter in the magpie_simple.php script, leading to XSS vulnerabilities.
No, CVE-2018-20171 is not present in Nagios XI version 5.5.8 or later, as those versions have addressed the vulnerability.
CVE-2018-20171 affects all versions of Nagios XI prior to version 5.5.8.