Record summary

CVE-2021-38156 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMNagios XI < 5.8.6 - Cross-Site ScriptingCVSS 5.4

In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.

Impact

Authenticated attackers can inject malicious JavaScript via XSS in the dashboard title field, potentially stealing administrator session cookies or performing administrative actions.

Remediation

Upgrade to Nagios XI version 5.8.6 or later.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2021nagiosnagiosxixssauthenticatedvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*
Shodan: http.title:"nagios xi"
FOFA: app="nagios-xi"
Google: intitle:"nagios xi"

Source: ProjectDiscovery

References

3