CVE-2020-10821: XSS
Published Mar 22, 2020
·Updated
Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter.
Affected Software
1 affected component
Nagios Nagios XI=5.6.11
Event History
Mar 22, 2020
CVE Published
via MITRE·07:53 PM
Data Sourced
via MITRE·07:53 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-10821.
2
What is the title of this vulnerability?
The title of this vulnerability is
3
What is the description of this vulnerability?
The description of this vulnerability is Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter.
4
What software is affected by this vulnerability?
Nagios XI 5.6.11 is affected by this vulnerability.
5
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is medium.
6
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The Common Weakness Enumeration (CWE) ID for this vulnerability is 79.
7
How can the vulnerability be exploited?
The vulnerability can be exploited by injecting malicious code through the theme parameter in the account/main.php page.
8
Is there a fix available for this vulnerability?
Yes, upgrading Nagios XI to a version that is not affected by this vulnerability will fix the issue.