CVE-2022-38248: XSS
Published Sep 7, 2022
·Updated
Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.
Affected Software
1 affected component
Nagios Nagios XI<5.8.7
Event History
Sep 7, 2022
CVE Published
via MITRE·09:14 PM
Data Sourced
via MITRE·09:14 PM
Description
Frequently Asked Questions
1
What is CVE-2022-38248?
CVE-2022-38248 is a vulnerability in Nagios XI before v5.8.7 that allows for multiple cross-site scripting (XSS) attacks.
2
What is the severity of CVE-2022-38248?
The severity of CVE-2022-38248 is medium with a CVSS score of 6.1.
3
What does CVE-2022-38248 affect?
CVE-2022-38248 affects Nagios XI before v5.8.7.
4
How can CVE-2022-38248 be exploited?
CVE-2022-38248 can be exploited through multiple cross-site scripting (XSS) attacks on the auditlog.php page.
5
How can CVE-2022-38248 be fixed?
To fix CVE-2022-38248, users should update to Nagios XI v5.8.7 or later.