← Zuruck zu CVEs
CVE-2023-40932
MEDIUM5.4
Beschreibung
A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the login page which means the attacker is able to to steal plaintext credentials.
CVE Details
CVSS v3.1 Bewertung5.4
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionREQUIRED
Veroffentlicht9/19/2023
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
nagios:nagios_xi
Schwachen (CWE)
CWE-79
Referenzen
http://nagios.com(cve@mitre.org)
https://outpost24.com/blog/nagios-xi-vulnerabilities/(cve@mitre.org)
https://www.nagios.com/products/security/(cve@mitre.org)
http://nagios.com(af854a3a-2127-422b-91ae-364da2661108)
https://outpost24.com/blog/nagios-xi-vulnerabilities/(af854a3a-2127-422b-91ae-364da2661108)
https://www.nagios.com/products/security/(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.