CVE-2024-54959: XSS
Published Feb 20, 2025
·Updated
Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS).
Affected Software
2 affected components
Nagios XI
Nagios Nagios XI=2024-r1.2.2
Event History
Feb 20, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-54959?
CVE-2024-54959 is classified as a high severity vulnerability due to its potential for exploitation via CSRF leading to XSS.
2
How do I fix CVE-2024-54959?
To fix CVE-2024-54959, update your Nagios XI to the latest version that addresses the CSRF vulnerability.
3
What impact does CVE-2024-54959 have on my Nagios XI installation?
CVE-2024-54959 allows attackers to execute unauthorized actions via CSRF, potentially compromising the integrity of the application.
4
Is CVE-2024-54959 specific to certain versions of Nagios XI?
Yes, CVE-2024-54959 specifically affects Nagios XI version 2024R1.2.2.
5
Can CVE-2024-54959 be exploited remotely?
Yes, CVE-2024-54959 can be exploited remotely, making it essential to apply mitigations quickly.