nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-38156 CVE-2021-38156
MEDIUMNuclei
Nagios XI < 5.8.6 - Cross-Site Scripting
Record summary
CVE-2021-38156 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.
Description
In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMNagios XI < 5.8.6 - Cross-Site ScriptingCVSS 5.4
In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.
Impact
Authenticated attackers can inject malicious JavaScript via XSS in the dashboard title field, potentially stealing administrator session cookies or performing administrative actions.
Remediation
Upgrade to Nagios XI version 5.8.6 or later.
WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2021nagiosnagiosxixssauthenticatedvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*
Shodan: http.title:"nagios xi"
FOFA: app="nagios-xi"
Google: intitle:"nagios xi"
Source: ProjectDiscovery
References
3raxis.com
https://raxis.com/blog/cve-2021-38156 nagios.com
https://www.nagios.com/downloads/nagios-xi/change-log