First published: Sun Mar 22 2020(Updated: )
Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Nagios XI | =5.6.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-10821.
The title of this vulnerability is
The description of this vulnerability is Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter.
Nagios XI 5.6.11 is affected by this vulnerability.
The severity rating of this vulnerability is medium.
The Common Weakness Enumeration (CWE) ID for this vulnerability is 79.
The vulnerability can be exploited by injecting malicious code through the theme parameter in the account/main.php page.
Yes, upgrading Nagios XI to a version that is not affected by this vulnerability will fix the issue.