CVE-2020-28903: XSS
Published May 24, 2021
·Updated
Improper input validation in Nagios Fusion 4.1.8 and earlier allows a remote attacker with control over a fused server to inject arbitrary HTML, aka XSS.
Affected Software
1 affected component
Nagios Fusion<=4.1.8
Event History
May 24, 2021
CVE Published
via MITRE·12:43 PM
Data Sourced
via MITRE·12:43 PM
Description
Frequently Asked Questions
1
What is CVE-2020-28903?
CVE-2020-28903 is a vulnerability in Nagios Fusion 4.1.8 and earlier that allows a remote attacker to inject arbitrary HTML.
2
What is the severity of CVE-2020-28903?
The severity of CVE-2020-28903 is medium, with a CVSS score of 6.1.
3
How does CVE-2020-28903 affect Nagios Fusion?
CVE-2020-28903 affects Nagios Fusion 4.1.8 and earlier versions.
4
What is the CWE classification of CVE-2020-28903?
CVE-2020-28903 is classified under CWE-79 (Cross-Site Scripting) and CWE-20 (Improper Input Validation).
5
How can I fix CVE-2020-28903 in Nagios Fusion?
To fix CVE-2020-28903 in Nagios Fusion, upgrade to a version later than 4.1.8 and apply any necessary patches.