Cross-Site Scripting Vulnerability in Nagios XI from Nagios
CVE-2016-15054
5.1MEDIUM
What is CVE-2016-15054?
Nagios XI versions before 5.4.0 have a vulnerability that allows cross-site scripting through the jQuery Migrate library. An attacker may exploit this flaw by supplying unvalidated input, which can lead to the execution of arbitrary scripts in the victim's browser. This breach of client-side security can enable attackers to hijack user sessions or manipulate user interactions with compromised web applications.
Affected Version(s)
XI 0 < 5.4.0
