Cross-Site Scripting Vulnerability in Nagios XI by Nagios
CVE-2011-10039 
5.1MEDIUM
What is CVE-2011-10039?
Nagios XI, an IT infrastructure monitoring tool, is affected by a cross-site scripting vulnerability that exists in the Alert Heatmap report and the 'My Reports' section of its web interface. Insufficient validation of user-input data allows attackers to inject malicious scripts, which can be executed in the context of a victim's browser. This vulnerability can lead to unauthorized actions on behalf of users, thereby compromising the integrity and confidentiality of their data.
Affected Version(s)
XI 0 < 2011R1.9
