CVE-2019-20139: XSS
Published Dec 30, 2019
·Updated
In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulereport.php hour or frequency parameter. Any authenticated user can attack the admin user.
Affected Software
1 affected component
Nagios Nagios XI=5.6.9
Event History
Dec 30, 2019
CVE Published
via MITRE·02:57 PM
Data Sourced
via MITRE·02:57 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20139?
CVE-2019-20139 is classified as a medium severity vulnerability.
2
How do I fix CVE-2019-20139?
To fix CVE-2019-20139, update Nagios XI to the latest version that resolves the XSS vulnerability.
3
What is the impact of CVE-2019-20139?
The impact of CVE-2019-20139 allows authenticated users to execute cross-site scripting attacks potentially targeting admin users.
4
Which versions of Nagios XI are affected by CVE-2019-20139?
CVE-2019-20139 affects Nagios XI version 5.6.9.
5
How can an attacker exploit CVE-2019-20139?
An attacker can exploit CVE-2019-20139 by sending crafted requests using the vulnerable parameters in the Nagios XI application.