Unauthenticated Vulnerabilities in Nagios XI's Highcharts Export Tool
CVE-2020-36862 
6.9MEDIUM
What is CVE-2020-36862?
Nagios XI versions before 5.6.11 are vulnerable to unauthenticated attacks due to issues in the Highcharts local exporting tool. An attacker can exploit these vulnerabilities by injecting scripts into exported content through inadequate output encoding, leading to Cross-Site Scripting (XSS). Additionally, they can trick the server into retrieving URLs specified by the attacker, which may facilitate the exposure of sensitive internal resources through Server-Side Request Forgery (SSRF). Users viewing the exported content could potentially have their browsers execute the malicious scripts, posing a significant risk to data integrity and confidentiality.
Affected Version(s)
XI 0 < 5.6.11
