Cross Site Scripting Vulnerability in Nagios XI by Nagios Enterprises
CVE-2020-23992
6.1MEDIUM
What is CVE-2020-23992?
A Cross Site Scripting (XSS) vulnerability exists in Nagios XI 5.7.1, allowing remote attackers to execute arbitrary code. This can be exploited by manipulating the returnUrl parameter in a targeted GET request. Successful exploitation could lead to unauthorized actions taken on behalf of the user, potentially compromising sensitive information and application integrity.