CVE-2019-9167: XSS
Published Mar 28, 2019
·Updated
Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow parameter.
Affected Software
1 affected component
Nagios Nagios XI<5.5.11
Event History
Mar 28, 2019
CVE Published
via MITRE·07:14 PM
Data Sourced
via MITRE·07:14 PM
Description
Data Sourced
via NVD·08:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-9167?
CVE-2019-9167 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2019-9167?
To fix CVE-2019-9167, upgrade Nagios XI to version 5.5.11 or later.
3
Who is affected by CVE-2019-9167?
CVE-2019-9167 affects all versions of Nagios XI prior to 5.5.11.
4
What type of attack does CVE-2019-9167 allow?
CVE-2019-9167 allows attackers to perform cross-site scripting attacks by injecting arbitrary web script or HTML.
5
When was CVE-2019-9167 reported?
CVE-2019-9167 was reported in 2019 and affects versions of Nagios XI before 5.5.11.