Cross-Site Scripting Vulnerability in Nagios XI by Nagios
CVE-2024-14001
5.1MEDIUM
What is CVE-2024-14001?
Nagios XI versions prior to 2024R1.1.3 are exposed to a cross-site scripting (XSS) vulnerability through the Executive Summary Report component. This occurs due to inadequate validation or escaping of user-supplied input, which may permit an attacker to inject and execute arbitrary scripts in the victim's browser context. This vulnerability poses significant risks, including data exposure and session hijacking, making timely updates essential for users of affected versions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
XI 0
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Márk Rákóczi
