CVE-2025-56432: XSS
A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to execute arbitrary JavaScript in the context of a logged-in user's session via a specially crafted URL. The issue resides in a web component responsible for rendering performance-related data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-56432?
CVE-2025-56432 is classified as a medium severity vulnerability due to its potential for exploiting users' sessions.
How do I fix CVE-2025-56432?
To fix CVE-2025-56432, ensure you are using the latest version of Nagios XI and apply any available security patches.
What type of vulnerability is CVE-2025-56432?
CVE-2025-56432 is a cross-site scripting (XSS) vulnerability that allows remote execution of arbitrary JavaScript.
Who is affected by CVE-2025-56432?
Users of Nagios XI version 2024R2 are affected by CVE-2025-56432.
What can attackers do with CVE-2025-56432?
Attackers can execute arbitrary JavaScript in the context of a logged-in user's session using a specially crafted URL.