CVE-2020-10819: XSS
Published Mar 22, 2020
·Updated
Nagios XI 5.6.11 allows XSS via the includes/components/ldapadintegration/ username parameter.
Affected Software
1 affected component
Nagios Nagios XI=5.6.11
Event History
Mar 22, 2020
CVE Published
via MITRE·07:53 PM
Data Sourced
via MITRE·07:53 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10819?
The severity of CVE-2020-10819 is medium with a CVSS score of 4.8.
2
How does CVE-2020-10819 affect Nagios XI?
CVE-2020-10819 affects Nagios XI version 5.6.11.
3
What is the vulnerability type of CVE-2020-10819?
CVE-2020-10819 is classified as a Cross-Site Scripting (XSS) vulnerability.
4
How can an attacker exploit CVE-2020-10819?
An attacker can exploit CVE-2020-10819 by injecting malicious code through the username parameter in the ldap_ad_integration component.
5
Is there a fix available for CVE-2020-10819?
Yes, upgrading Nagios XI to a version beyond 5.6.11 will fix CVE-2020-10819.