assets.nagios.com
https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT CVE-2022-29272
MEDIUMNuclei
Nagios XI <5.8.5 - Open Redirect
Record summary
CVE-2022-29272 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMNagios XI <5.8.5 - Open RedirectCVSS 6.1
Nagios XI through 5.8.5 contains an open redirect vulnerability in the login function. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks.
Remediation
Upgrade Nagios XI to version 5.8.5 or later to mitigate the vulnerability.
WeaknessesCWE-601
Authorsritikchaddha
Template tagscvecve2022redirectnagiosnagiosxivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*
Shodan: http.title:"nagios xi"
FOFA: title="nagios xi"
FOFA: app="nagios-xi"
Google: intitle:"nagios xi"
https://github.com/sT0wn-nl/CVEs/tree/master/CVE-2022-29272 https://github.com/4LPH4-NL/CVEs https://github.com/sT0wn-nl/CVEs/blob/master/README.md#nagios-xi https://nvd.nist.gov/vuln/detail/CVE-2022-29272 https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT
Source: ProjectDiscovery
References
5github.com
https://github.com/4LPH4-NL/CVEs github.com
https://github.com/sT0wn-nl/CVEs/blob/master/README.md nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-29272 nagios.com
https://www.nagios.com/downloads/nagios-xi/change-log