CVE-2022-38251: XSS
Published Sep 7, 2022
·Updated
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Performance Settings page under the Admin panel.
Affected Software
1 affected component
Nagios Nagios XI=5.8.6
Event History
Sep 7, 2022
CVE Published
via MITRE·09:14 PM
Data Sourced
via MITRE·09:14 PM
Description
Frequently Asked Questions
1
What is CVE-2022-38251?
CVE-2022-38251 is a cross-site scripting (XSS) vulnerability discovered in Nagios XI v5.8.6.
2
How does the cross-site scripting (XSS) vulnerability in Nagios XI v5.8.6 occur?
The cross-site scripting (XSS) vulnerability in Nagios XI v5.8.6 can be exploited via the System Performance Settings page under the Admin panel.
3
What is the severity of CVE-2022-38251?
CVE-2022-38251 has a severity rating of medium (4.8).
4
How can I fix the cross-site scripting (XSS) vulnerability in Nagios XI v5.8.6?
To fix the cross-site scripting (XSS) vulnerability in Nagios XI v5.8.6, you should update to version 5.8.7, which contains a fix for this vulnerability.
5
Where can I find more information about CVE-2022-38251?
You can find more information about CVE-2022-38251 in the Nagios XI v5.8.7 change log: https://www.nagios.com/downloads/nagios-xi/change-log/#5.8.7