#VU36402 Cross-site scripting in Nagios XI - CVE-2018-15714

 

#VU36402 Cross-site scripting in Nagios XI - CVE-2018-15714

Published: November 14, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU36402
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
CVE-ID: CVE-2018-15714
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Nagios XI
Software vendor:
nagios.org

Description

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.


Remediation

Install update from vendor's website.

External links