CVE-2024-42898: XSS
Published Jan 9, 2025
·Updated
A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Account Settings page.
Affected Software
2 affected components
Nagios XI
Nagios Nagios XI=2024-r1.1.4
Event History
Jan 9, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-42898?
CVE-2024-42898 is classified as a medium severity vulnerability due to its potential impact on web security.
2
How do I fix CVE-2024-42898?
To mitigate CVE-2024-42898, users should update Nagios XI to the latest version provided by the vendor that addresses this XSS vulnerability.
3
What is the impact of CVE-2024-42898?
CVE-2024-42898 allows attackers to execute arbitrary web scripts or HTML, which can lead to data theft or session hijacking.
4
In which version of Nagios does CVE-2024-42898 exist?
CVE-2024-42898 exists in Nagios XI version 2024R1.1.4.
5
Where is the vulnerability located in Nagios XI related to CVE-2024-42898?
CVE-2024-42898 is located in the Name parameter on the Account Settings page of Nagios XI.