Total
98 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2021-25299 | 1 Nagios | 1 Nagios Xi | 2021-03-04 | 4.3 MEDIUM | 6.1 MEDIUM |
Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal his/her session cookies or it can be chained with the previous bugs to get one-click remote command execution (RCE) on the Nagios XI server. | |||||
CVE-2021-3273 | 1 Nagios | 1 Nagios Xi | 2021-03-02 | 9.0 HIGH | 7.2 HIGH |
Nagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component. To exploit this vulnerability, someone must have an admin user account in Nagios XI's web system. | |||||
CVE-2021-26023 | 1 Nagios | 2 Favorites, Nagios Xi | 2021-02-05 | 4.3 MEDIUM | 6.1 MEDIUM |
The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS. | |||||
CVE-2021-3193 | 1 Nagios | 1 Nagios Xi | 2021-02-03 | 7.5 HIGH | 9.8 CRITICAL |
Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated attacker to execute remote code as the apache user. | |||||
CVE-2020-5796 | 1 Nagios | 1 Nagios Xi | 2020-11-24 | 7.2 HIGH | 7.8 HIGH |
Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the permissions of files, resulting in low-privileged users being able to write to and execute arbitrary PHP code with root privileges. | |||||
CVE-2020-27988 | 1 Nagios | 1 Nagios Xi | 2020-11-17 | 3.5 LOW | 5.4 MEDIUM |
Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field). | |||||
CVE-2020-27989 | 1 Nagios | 1 Nagios Xi | 2020-11-17 | 3.5 LOW | 5.4 MEDIUM |
Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard). | |||||
CVE-2020-27990 | 1 Nagios | 1 Nagios Xi | 2020-11-17 | 3.5 LOW | 5.4 MEDIUM |
Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent). | |||||
CVE-2020-27991 | 1 Nagios | 1 Nagios Xi | 2020-11-17 | 3.5 LOW | 5.4 MEDIUM |
Nagios XI before 5.7.5 is vulnerable to XSS in Account Information (Email field). | |||||
CVE-2020-5790 | 1 Nagios | 1 Nagios Xi | 2020-10-21 | 4.3 MEDIUM | 6.5 MEDIUM |
Cross-site request forgery in Nagios XI 5.7.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link. | |||||
CVE-2018-10554 | 1 Nagios | 1 Nagios Xi | 2020-08-24 | 3.5 LOW | 5.4 MEDIUM |
An issue was discovered in Nagios XI 5.4.13. There is XSS exploitable via CSRF in (1) the Schedule New Report screen via the hour, minute, or ampm parameter, related to components/scheduledreporting; (2) includes/components/xicore/downtime.php, related to the update_pages function; (3) the ajaxhelper.php opts or background parameter; (4) the i[] array parameter to ajax_handler.php; or (5) the deploynotification.php title parameter. | |||||
CVE-2020-10821 | 1 Nagios | 1 Nagios Xi | 2020-03-23 | 3.5 LOW | 4.8 MEDIUM |
Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter. | |||||
CVE-2020-10820 | 1 Nagios | 1 Nagios Xi | 2020-03-23 | 3.5 LOW | 4.8 MEDIUM |
Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ password parameter. | |||||
CVE-2020-10819 | 1 Nagios | 1 Nagios Xi | 2020-03-23 | 3.5 LOW | 4.8 MEDIUM |
Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ username parameter. | |||||
CVE-2019-20197 | 1 Nagios | 1 Nagios Xi | 2020-01-07 | 9.0 HIGH | 8.8 HIGH |
In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account. | |||||
CVE-2019-20139 | 1 Nagios | 1 Nagios Xi | 2020-01-03 | 3.5 LOW | 5.4 MEDIUM |
In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulereport.php hour or frequency parameter. Any authenticated user can attack the admin user. | |||||
CVE-2018-15711 | 1 Nagios | 1 Nagios Xi | 2019-10-03 | 6.5 MEDIUM | 8.8 HIGH |
Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then use the new API key to execute API calls at elevated privileges. | |||||
CVE-2018-15710 | 1 Nagios | 1 Nagios Xi | 2019-10-03 | 7.2 HIGH | 7.8 HIGH |
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php. | |||||
CVE-2018-15708 | 1 Nagios | 1 Nagios Xi | 2019-10-03 | 7.5 HIGH | 9.8 CRITICAL |
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request. | |||||
CVE-2018-8736 | 1 Nagios | 1 Nagios Xi | 2019-10-03 | 9.0 HIGH | 8.8 HIGH |
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RCE vulnerability escalating to root. |