CVE-2023-7314: Nagios XI < 5.11.3 XSS via Bandwidth Report
Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bandwidth Report component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nagios XIto a version that resolves this vulnerability.Fixed in 5.11.3
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7314?
CVE-2023-7314 is classified as a medium severity vulnerability due to its potential impact on user security through cross-site scripting.
How do I fix CVE-2023-7314?
To fix CVE-2023-7314, update Nagios XI to version 5.11.3 or later where the vulnerability has been addressed.
What does CVE-2023-7314 affect?
CVE-2023-7314 affects all versions of Nagios XI prior to 5.11.3, specifically through the Bandwidth Report component.
What type of vulnerability is CVE-2023-7314?
CVE-2023-7314 is a cross-site scripting (XSS) vulnerability allowing attackers to inject malicious scripts into user browsers.
How does CVE-2023-7314 exploit user input?
CVE-2023-7314 exploits insufficient validation or escaping of user-supplied input in the Bandwidth Report component of Nagios XI.