Junglewise Threat Intelligence

CVE-2023-24034: Nagios XI open redirect in twilio_ajax_handler.php

CVE-2023-24034 · Severity: low · CVSS 3.1 · Published 2026-09-14

Technologies: Nagios XI. Vendors: Nagios.

Executive brief

Nagios XI is an enterprise monitoring platform that tracks infrastructure performance and alerts. The vulnerability allows an attacker to trick users into visiting malicious websites through a redirect flaw, potentially redirecting administrators away from legitimate sites to phishing pages or malware distributors.

Technical details

An open redirect vulnerability exists in twilio_ajax_handler.php in Nagios XI before version 5.9.3. The vulnerability allows an attacker to craft a malicious URL that, when visited by a user, redirects them to an arbitrary attacker-controlled website. This is a client-side redirect that relies on user interaction (clicking a link) and does not require authentication to trigger. The attack vector is network-based, typically leveraging phishing or social engineering to deliver the malicious link. No remote code execution or direct system compromise occurs, but the redirect can facilitate credential theft or malware distribution.

Affected products

  • Nagios Nagios XI before 5.9.3

Timeline

  • 2026-09-14: disclosed
  • 2023: patched: Fixed in Nagios XI 5.9.3

References

Related threats