CVE-2021-47697: Nagios XI < 5.8.0 XSS via Views URL Handling
Nagios XI versions prior to 5.8.0 are vulnerable to cross-site scripting (XSS) via the Views feature URL handling. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47697?
CVE-2021-47697 has a medium severity level due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2021-47697?
To fix CVE-2021-47697, upgrade Nagios XI to version 5.8.0 or later.
What types of attacks are possible with CVE-2021-47697?
CVE-2021-47697 allows for cross-site scripting (XSS) attacks, enabling attackers to execute arbitrary scripts in a victim's browser.
Which versions of Nagios XI are affected by CVE-2021-47697?
Nagios XI versions prior to 5.8.0 are vulnerable to CVE-2021-47697.
What is the context in which CVE-2021-47697 allows script execution?
CVE-2021-47697 allows script execution in the context of the victim's browser due to insufficient validation of user-supplied input in the Views feature.