Executive brief
Nagios XI is an enterprise monitoring solution used to track infrastructure health and performance. A cross-site scripting vulnerability in the Bulk Modifications tool allows attackers to inject malicious scripts that execute in administrators' browsers, potentially enabling session hijacking, credential theft, or unauthorized configuration changes to monitored systems.
Technical details
This is a stored or reflected cross-site scripting (XSS) vulnerability in the Bulk Modifications component of Nagios XI. The root cause is insufficient validation and escaping of user-supplied input before rendering it in the web interface. An attacker can craft a malicious request via the Bulk Modifications tool containing JavaScript payload; when a victim (typically an administrator) views or processes the modification, the script executes in their browser context with their privileges. This allows session hijacking, credential theft, or unauthorized administrative actions. The vulnerability affects Nagios XI versions prior to 5.11.3; a patch is available in version 5.11.3 and later.
Affected products
- Nagios XI prior to 5.11.3
Timeline
- 2025-10-30: disclosed
- 2023: patched: Fixed in version 5.11.3