CVE-2023-24034: Low severity Nagios XI vulnerability
Published Sep 14, 2026
·Updated
An issue was discovered in twilioajaxhandler.php in Nagios XI before 5.9.3. An attacker can force a user to visit a malicious site by using a open redirect vulnerability.
Affected Software
1 affected component
Nagios XI<5.9.3
Event History
Sep 14, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Nagios XI versions before 5.9.3 are affected. The issue is in twilio_ajax_handler.php.
2
What does an attacker need to exploit this issue?
An attacker must get a user to visit a malicious site. The CVSS vector indicates exploitation is network-based, requires high attack complexity, needs no privileges, and requires user interaction.
3
What is the impact of successful exploitation?
Successful exploitation can force a user to be redirected to a malicious site. The stated CVSS impact is limited to integrity, with no confidentiality or availability impact.