CVE-2021-25299: XSS
Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal his/her session cookies or it can be chained with the previous bugs to get one-click remote command execution (RCE) on the Nagios XI server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nagios XIto a version that resolves this vulnerability.Fixed in xi-5.7.5
Event History
Frequently Asked Questions
What is the vulnerability ID for this Nagios XI vulnerability?
The vulnerability ID for this Nagios XI vulnerability is CVE-2021-25299.
What is the severity of CVE-2021-25299?
The severity of CVE-2021-25299 is medium with a CVSS score of 6.1.
Which version of Nagios XI is affected by CVE-2021-25299?
Nagios XI version xi-5.7.5 is affected by CVE-2021-25299.
What is the CWE-ID associated with CVE-2021-25299?
The CWE-ID associated with CVE-2021-25299 is CWE-79 (Cross-Site Scripting).
How can I fix the cross-site scripting vulnerability in Nagios XI version xi-5.7.5?
To fix the cross-site scripting vulnerability in Nagios XI version xi-5.7.5, apply the latest security patches or upgrade to a patched version of the software.