Junglewise Threat Intelligence

CVE-2025-56432: Nagios XI cross-site scripting in performance data component

CVE-2025-56432 · Severity: medium · CVSS 6.1 · Published 2025-08-26

Technologies: Nagios XI. Vendors: Nagios.

Executive brief

Nagios XI, a popular IT infrastructure monitoring platform, is affected by a security flaw in its performance data rendering component. An attacker could trick a logged-in user into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the user's browser. This could lead to the theft of session information or unauthorized actions performed on behalf of the user within the monitoring system.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Nagios XI version 2024R2. The flaw is located within the web component responsible for rendering performance-related data, which fails to properly neutralize user-supplied input before including it in the generated web page. An unauthenticated remote attacker can exploit this by inducing a logged-in user to visit a specially crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized configuration changes. The vulnerability is tracked as CWE-79.

Affected products

  • Nagios Nagios XI 2024R2

Timeline

  • 2025-08-26: advisory: NVD published the vulnerability record.

References

Related threats