Unauthenticated Vulnerabilities in Nagios XI's Highcharts Export Tool
CVE-2020-36862

6.9MEDIUM

Key Information:

Vendor

NagiOS

Status
Vendor
CVE Published:
30 October 2025

What is CVE-2020-36862?

Nagios XI versions before 5.6.11 are vulnerable to unauthenticated attacks due to issues in the Highcharts local exporting tool. An attacker can exploit these vulnerabilities by injecting scripts into exported content through inadequate output encoding, leading to Cross-Site Scripting (XSS). Additionally, they can trick the server into retrieving URLs specified by the attacker, which may facilitate the exposure of sensitive internal resources through Server-Side Request Forgery (SSRF). Users viewing the exported content could potentially have their browsers execute the malicious scripts, posing a significant risk to data integrity and confidentiality.

Affected Version(s)

XI 0 < 5.6.11

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-36862 : Unauthenticated Vulnerabilities in Nagios XI's Highcharts Export Tool