CVE-2018-20171: XSS
Published Dec 17, 2018
·Updated
An issue was discovered in Nagios XI before 5.5.8. The url parameter of rssdashlet/magpierss/scripts/magpiesimple.php is not filtered, resulting in an XSS vulnerability.
Affected Software
1 affected component
Nagios Nagios XI<5.5.8
Event History
Dec 17, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20171?
CVE-2018-20171 is classified as a medium-severity vulnerability due to its potential for exploitation through cross-site scripting (XSS).
2
How do I fix CVE-2018-20171?
To fix CVE-2018-20171, upgrade Nagios XI to version 5.5.8 or later to ensure the vulnerability is patched.
3
What does CVE-2018-20171 exploit in Nagios XI?
CVE-2018-20171 exploits an unfiltered url parameter in the magpie_simple.php script, leading to XSS vulnerabilities.
4
Is CVE-2018-20171 present in Nagios XI version 5.5.8?
No, CVE-2018-20171 is not present in Nagios XI version 5.5.8 or later, as those versions have addressed the vulnerability.
5
Which versions of Nagios XI are affected by CVE-2018-20171?
CVE-2018-20171 affects all versions of Nagios XI prior to version 5.5.8.