CVE-2020-23992: XSS
Published Aug 22, 2023
·Updated
Cross Site Scripting (XSS) in Nagios XI 5.7.1 allows remote attackers to run arbitrary code via returnUrl parameter in a crafted GET request.
Affected Software
1 affected component
Nagios Nagios XI=5.7.1
Event History
Aug 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-23992.
2
What is the severity level of CVE-2020-23992?
The severity level of CVE-2020-23992 is medium.
3
What is the vulnerability description of CVE-2020-23992?
CVE-2020-23992 is a Cross Site Scripting (XSS) vulnerability in Nagios XI 5.7.1 that allows remote attackers to run arbitrary code via the returnUrl parameter in a crafted GET request.
4
How can the vulnerability be exploited?
The vulnerability can be exploited by sending a specially crafted GET request with a malicious returnUrl parameter.
5
Is there a fix available for CVE-2020-23992?
Yes, a fix is available for CVE-2020-23992. It is recommended to update to a version of Nagios XI that is not affected by this vulnerability.