CVE-2021-47698: Nagios XI < 5.8.7 XSS in Core UI Views URL handling
Nagios XI versions prior to 5.8.7 using embedded Nagios Core are vulnerable to cross-site scripting (XSS) via the Core UI’s Views URL handling (escapestring()). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47698?
CVE-2021-47698 is classified as a critical vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2021-47698?
To fix CVE-2021-47698, upgrade Nagios XI to version 5.8.7 or later.
What are the potential impacts of CVE-2021-47698?
CVE-2021-47698 may allow attackers to inject and execute arbitrary scripts, leading to unauthorized access and data manipulation.
Which versions of Nagios XI are affected by CVE-2021-47698?
Nagios XI versions prior to 5.8.7 are vulnerable to CVE-2021-47698.
What type of attack does CVE-2021-47698 facilitate?
CVE-2021-47698 facilitates cross-site scripting (XSS) attacks due to insufficient input validation.