First published: Mon Feb 15 2021(Updated: )
Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal his/her session cookies or it can be chained with the previous bugs to get one-click remote command execution (RCE) on the Nagios XI server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Nagios XI | =5.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Nagios XI vulnerability is CVE-2021-25299.
The severity of CVE-2021-25299 is medium with a CVSS score of 6.1.
Nagios XI version xi-5.7.5 is affected by CVE-2021-25299.
The CWE-ID associated with CVE-2021-25299 is CWE-79 (Cross-Site Scripting).
To fix the cross-site scripting vulnerability in Nagios XI version xi-5.7.5, apply the latest security patches or upgrade to a patched version of the software.