Cross-Site Scripting in Nagios XI by Nagios
CVE-2020-36866 
5.1MEDIUM
What is CVE-2020-36866?
Nagios XI, a leading IT monitoring platform, is susceptible to cross-site scripting (XSS) attacks in versions before 5.7.2. The vulnerability arises on the Manage Users page within the Admin interface, where inadequate validation or escaping of user-supplied inputs can enable attackers to inject and execute arbitrary scripts. This exploitation may compromise the security of users by allowing unauthorized actions within their browsers. It's essential for administrators to update to the latest version to mitigate this risk.
Affected Version(s)
XI 0 < 5.7.2
