← Back

CVE-2011-10038

nvd nist
Published: Oct 30, 2025Modified: Nov 6, 2025

JSON object

Loading...
5.1
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: disclosure@vulncheck.com (Secondary)

Description

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the recurring downtime script of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

Affected (10)

Products: Nagios: Nagios Xi
1 product
Nagios Xi
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Nagios
Up to 2009
Version 2011 r1.1
Version 2011 r1.2
Version 2011 r1.3
Version 2011 r1.4
Version 2011 r1.5
Version 2011 r1.6
Version 2011 r1.7
Version 2011 r1.8
Version 2011 r1

References (2)

Source: disclosure@vulncheck.com
Release Notes

Timeline

No history available yet.