First published: Thu Jan 09 2025(Updated: )
A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Account Settings page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42898 is classified as a medium severity vulnerability due to its potential impact on web security.
To mitigate CVE-2024-42898, users should update Nagios XI to the latest version provided by the vendor that addresses this XSS vulnerability.
CVE-2024-42898 allows attackers to execute arbitrary web scripts or HTML, which can lead to data theft or session hijacking.
CVE-2024-42898 exists in Nagios XI version 2024R1.1.4.
CVE-2024-42898 is located in the Name parameter on the Account Settings page of Nagios XI.