Cross-Site Scripting in Nagios XI by Nagios
CVE-2020-36866

5.1MEDIUM

Key Information:

Vendor

NagiOS

Status
Vendor
CVE Published:
30 October 2025

What is CVE-2020-36866?

Nagios XI, a leading IT monitoring platform, is susceptible to cross-site scripting (XSS) attacks in versions before 5.7.2. The vulnerability arises on the Manage Users page within the Admin interface, where inadequate validation or escaping of user-supplied inputs can enable attackers to inject and execute arbitrary scripts. This exploitation may compromise the security of users by allowing unauthorized actions within their browsers. It's essential for administrators to update to the latest version to mitigate this risk.

Affected Version(s)

XI 0 < 5.7.2

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Christian Weiler
.
CVE-2020-36866 : Cross-Site Scripting in Nagios XI by Nagios