CVE-2019-20139
In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulereport.php hour or frequency parameter. Any authenticated user can attack the admin user.
Published
2019-12-30T15:15:10.767
Last Modified
2024-11-21T04:38:04.940
Status
Modified
Source
[email protected]
Severity
CVSSv3.1: 5.4 (MEDIUM)
CVSSv2 Vector
AV:N/AC:M/Au:S/C:N/I:P/A:N
- Access Vector: NETWORK
- Access Complexity: MEDIUM
- Authentication: SINGLE
- Confidentiality Impact: NONE
- Integrity Impact: PARTIAL
- Availability Impact: NONE
Exploitability Score
6.8
Impact Score
2.9
Weaknesses
Affected Vendors & Products
Type |
Vendor |
Product |
Version/Range |
Vulnerable? |
Application |
nagios
|
nagios_xi
|
5.6.9 |
Yes
|
References