Unauthenticated Vulnerabilities in Nagios XI's Highcharts Export Tool
CVE-2020-36862

6.9MEDIUM

Key Information:

Vendor

NagiOS

Status
Vendor
CVE Published:
30 October 2025

What is CVE-2020-36862?

Nagios XI versions before 5.6.11 are vulnerable to unauthenticated attacks due to issues in the Highcharts local exporting tool. An attacker can exploit these vulnerabilities by injecting scripts into exported content through inadequate output encoding, leading to Cross-Site Scripting (XSS). Additionally, they can trick the server into retrieving URLs specified by the attacker, which may facilitate the exposure of sensitive internal resources through Server-Side Request Forgery (SSRF). Users viewing the exported content could potentially have their browsers execute the malicious scripts, posing a significant risk to data integrity and confidentiality.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

XI 0 < 5.6.11

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.