CVE-2024-54957: Medium severity nagios vulnerability
Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permissions. This vulnerability allows an attacker to craft a malicious link that redirects users to an arbitrary external URL without their consent.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54957?
CVE-2024-54957 is classified as a moderate severity vulnerability due to its exploitation potential by users with read-only permissions.
How do I fix CVE-2024-54957?
To fix CVE-2024-54957, update Nagios XI to the latest version that includes a patch for this vulnerability.
Who is affected by CVE-2024-54957?
CVE-2024-54957 affects Nagios XI users, particularly those with read-only permissions.
What is an open redirect vulnerability in the context of CVE-2024-54957?
An open redirect vulnerability allows an attacker to redirect users to an arbitrary external URL without their consent, as seen in CVE-2024-54957.
Can CVE-2024-54957 be exploited by unauthorized users?
No, CVE-2024-54957 can only be exploited by users who have read-only permissions in Nagios XI.