Executive brief
Nagios XI, a popular IT infrastructure monitoring platform, is affected by a security flaw in its performance data rendering component. An attacker could trick a logged-in user into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the user's browser. This could lead to the theft of session information or unauthorized actions performed on behalf of the user within the monitoring system.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in Nagios XI version 2024R2. The flaw is located within the web component responsible for rendering performance-related data, which fails to properly neutralize user-supplied input before including it in the generated web page. An unauthenticated remote attacker can exploit this by inducing a logged-in user to visit a specially crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized configuration changes. The vulnerability is tracked as CWE-79.
Affected products
- Nagios Nagios XI 2024R2
Timeline
- 2025-08-26: advisory: NVD published the vulnerability record.