← Back

CVE-2024-54958

nvd nist
Published: Feb 20, 2025Modified: Jul 1, 2025

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts into the Tools interface, which are then stored and executed in the context of other users accessing the page.

Affected (1)

Products: Nagios: Nagios Xi
1 product
Nagios Xi
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2024 r1.2.2

References (1)

Source: cve@mitre.org
Third Party Advisory

Timeline

No history available yet.