Cross-Site Scripting Vulnerability in Nagios XI by Nagios
CVE-2024-14001

5.1MEDIUM

Key Information:

Vendor

NagiOS

Status
Vendor
CVE Published:
30 October 2025

What is CVE-2024-14001?

Nagios XI versions prior to 2024R1.1.3 are exposed to a cross-site scripting (XSS) vulnerability through the Executive Summary Report component. This occurs due to inadequate validation or escaping of user-supplied input, which may permit an attacker to inject and execute arbitrary scripts in the victim's browser context. This vulnerability poses significant risks, including data exposure and session hijacking, making timely updates essential for users of affected versions.

Affected Version(s)

XI 0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Márk Rákóczi
.
CVE-2024-14001 : Cross-Site Scripting Vulnerability in Nagios XI by Nagios