#VU27087 Overly permissive cross-domain whitelist in Nagios XI
Published: April 22, 2020
Nagios XI
nagios.org
Description
The vulnerability allows a remote attacker to bypass security restriction.
The vulnerability exists due to insecure CORS policy that allows a remote attacker to send HTTP requests from arbitrary domain name within the API. A remote non-authenticated attacker can bypass browser security restrictions and send requests to the API endpoints on behalf of the victim.