First published: Thu Feb 27 2025(Updated: )
Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permissions. This vulnerability allows an attacker to craft a malicious link that redirects users to an arbitrary external URL without their consent.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-54957 is classified as a moderate severity vulnerability due to its exploitation potential by users with read-only permissions.
To fix CVE-2024-54957, update Nagios XI to the latest version that includes a patch for this vulnerability.
CVE-2024-54957 affects Nagios XI users, particularly those with read-only permissions.
An open redirect vulnerability allows an attacker to redirect users to an arbitrary external URL without their consent, as seen in CVE-2024-54957.
No, CVE-2024-54957 can only be exploited by users who have read-only permissions in Nagios XI.