Cross-Site Scripting Vulnerability in Nagios XI by Nagios
CVE-2013-10074 
5.1MEDIUM
What is CVE-2013-10074?
Nagios XI versions prior to 2012R2.6 are susceptible to a cross-site scripting vulnerability through the Tools Menu of the web interface. This flaw arises from inadequate validation or escaping of user-supplied input, potentially enabling an attacker to inject and execute arbitrary scripts within the context of a victim's browser, compromising user data and security.
Affected Version(s)
XI 0 < 2012R2.6
