Back

MEDIUM

A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field

Published Sep 19, 2023

Description

A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the login page which means the attacker is able to to steal plaintext credentials.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Sep 19, 2023
Updated Jul 9, 2026
Reserved Aug 22, 2023

CISA Vulnrichment

Updated Sep 24, 2024

NVD

Status Modified
Modified Jul 9, 2026

Red Hat

No data

ENISA EUVD

Assigner mitre
Published Sep 19, 2023
Updated Jul 9, 2026

GitHub

No data