CVE-2024-13992: Nagios XI < 2024R1.1 XSS via Missing Page / 404
Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing page" (404) page after following a link from another website. The vulnerable component, page-missing.php, fails to properly validate or escape user-supplied input, allowing an attacker to craft a malicious link that, when visited by a victim, executes arbitrary JavaScript in the victim’s browser within the Nagios XI domain.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13992?
The severity of CVE-2024-13992 is classified as medium due to the potential for cross-site scripting vulnerabilities.
How do I fix CVE-2024-13992?
To fix CVE-2024-13992, update Nagios XI to version 2024R1.1 or later.
Which versions of Nagios XI are affected by CVE-2024-13992?
Nagios XI versions prior to 2024R1.1 are affected by CVE-2024-13992.
What component is vulnerable in CVE-2024-13992?
The vulnerable component in CVE-2024-13992 is page-missing.php.
What type of vulnerability is CVE-2024-13992?
CVE-2024-13992 is a cross-site scripting (XSS) vulnerability.