CVE-2023-53688

MEDIUM

Nagios XI <5.11.3 - XSS/CSRF

Title source: llm

Description

Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) and cross-site request forgery (CSRF) via the Hypermap Replay component. An attacker can submit crafted input that is not properly validated or escaped, allowing injection of malicious script that executes in the context of a victim's browser (XSS). Additionally, the component does not enforce sufficient anti-CSRF protections on state-changing operations, enabling an attacker to induce authenticated users to perform unwanted actions.

Scores

CVSS v3 5.4
EPSS 0.0011
EPSS Percentile 30.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Classification

CWE
CWE-352 CWE-79
Status published

Affected Products (1)

nagios/nagios_xi < 5.11.3

Timeline

Published Oct 30, 2025
Tracked Since Feb 18, 2026