CVE-2024-54958: XSS
Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts into the Tools interface, which are then stored and executed in the context of other users accessing the page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54958?
CVE-2024-54958 is classified as a stored Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2024-54958?
To fix CVE-2024-54958, update Nagios XI to the latest version that addresses this XSS vulnerability.
Who is affected by CVE-2024-54958?
CVE-2024-54958 affects all users of Nagios XI version 2024R1.2.2.
What are the potential impacts of CVE-2024-54958?
The potential impacts of CVE-2024-54958 include session hijacking and unauthorized access to sensitive information.
Is CVE-2024-54958 related to user roles in Nagios XI?
Yes, CVE-2024-54958 can exploit stored scripts that are executed when other users access the Tools page, regardless of their user roles.