Reflected Cross-Site Scripting Vulnerability in Nagios XI
CVE-2013-10071

5.1MEDIUM

Key Information:

Vendor

NagiOS

Status
Vendor
CVE Published:
30 October 2025

What is CVE-2013-10071?

Nagios XI versions prior to 2012R1.6 are susceptible to a reflected cross-site scripting vulnerability found in the dashboard dashlet's AJAX load functionality. This security flaw arises from improper validation or escaping of user-supplied input. As a result, an attacker could potentially inject malicious scripts, which would subsequently execute within the browser environment of a victim, leading to various security risks, including unauthorized access to sensitive information.

Affected Version(s)

XI 0 < 2012R1.6

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

James Clawson
.
CVE-2013-10071 : Reflected Cross-Site Scripting Vulnerability in Nagios XI