CVE-2018-25121: Nagios XI < 5.4.13 XSS via Views Page
Published Oct 30, 2025
·Updated
Nagios XI versions prior to 5.4.13 are vulnerable to cross-site scripting (XSS) via the Views page of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
Affected Software
2 affected components
Nagios Nagios XI<5.4.13
Nagios Nagios XI<5.4.13
Remediation
Information
Nagios addresses this vulnerability as "Fixed XSS vulnerability in views page."
Event History
Oct 30, 2025
CVE Published
via MITRE·09:56 PM
Data Sourced
via MITRE·09:56 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-25121?
CVE-2018-25121 is classified as a high severity vulnerability due to its potential to allow cross-site scripting (XSS) attacks.
2
How do I fix CVE-2018-25121?
To fix CVE-2018-25121, upgrade Nagios XI to version 5.4.13 or later.
3
What versions of Nagios XI are affected by CVE-2018-25121?
Nagios XI versions prior to 5.4.13 are affected by CVE-2018-25121.
4
What type of vulnerability is CVE-2018-25121?
CVE-2018-25121 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2018-25121 lead to data compromise?
Yes, CVE-2018-25121 can lead to data compromise by allowing attackers to execute arbitrary scripts in a victim's browser.