Record summary

CVE-2022-29272 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMNagios XI <5.8.5 - Open RedirectCVSS 6.1

Nagios XI through 5.8.5 contains an open redirect vulnerability in the login function. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks.

Remediation

Upgrade Nagios XI to version 5.8.5 or later to mitigate the vulnerability.

WeaknessesCWE-601
Authorsritikchaddha
Template tagscvecve2022redirectnagiosnagiosxivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*
Shodan: http.title:"nagios xi"
FOFA: title="nagios xi"
FOFA: app="nagios-xi"
Google: intitle:"nagios xi"

Source: ProjectDiscovery

References

5