Junglewise Threat Intelligence

CVE-2023-7314: Nagios XI cross-site scripting in Bandwidth Report

CVE-2023-7314 · Severity: medium · CVSS 5.4 · Published 2025-10-30

Technologies: Nagios XI. Vendors: Nagios.

Executive brief

Nagios XI is an enterprise monitoring solution used by organizations to track infrastructure health and performance. A cross-site scripting (XSS) vulnerability in its Bandwidth Report component allows attackers to inject malicious scripts that execute in users' browsers, potentially enabling session hijacking, credential theft, or unauthorized actions within the monitoring system.

Technical details

The vulnerability is a reflected or stored cross-site scripting (XSS) flaw in the Bandwidth Report component of Nagios XI caused by insufficient validation and escaping of user-supplied input. An attacker can craft malicious input (typically via URL parameters or form fields in the report) that gets rendered without proper HTML/JavaScript encoding. When a victim accesses the malicious report link, the injected script executes in their browser context with the same privileges as the user. The vulnerability affects Nagios XI versions prior to 5.11.3, which introduced fixes for input sanitization and output encoding. An attacker needs network access to the Nagios XI web interface but does not require authentication to craft a malicious URL; however, victim interaction (clicking the link) is typically required for exploitation.

Affected products

  • Nagios XI prior to 5.11.3

Timeline

  • 2025-10-30: disclosed

References

Related threats