CVE-2022-38254: XSS
Published Sep 7, 2022
·Updated
Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5.
Affected Software
1 affected component
Nagios Nagios XI<5.8.7
Event History
Sep 7, 2022
CVE Published
via MITRE·09:14 PM
Data Sourced
via MITRE·09:14 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Nagios XI vulnerability?
The vulnerability ID is CVE-2022-38254.
2
What is the title of this Nagios XI vulnerability?
The title of the vulnerability is 'Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability'.
3
What is the severity of this Nagios XI vulnerability?
The severity of this vulnerability is medium with a CVSS score of 6.1.
4
What is the affected software version range for this Nagios XI vulnerability?
The affected software version range is Nagios XI up to and excluding v5.8.7.
5
How can I fix this Nagios XI vulnerability?
To fix this vulnerability, you need to upgrade Nagios XI to version 5.8.7 or higher.