CVE-2020-23992
- EPSS 0.86%
- Veröffentlicht 22.08.2023 19:16:19
- Zuletzt bearbeitet 21.11.2024 05:14:18
Cross Site Scripting (XSS) in Nagios XI 5.7.1 allows remote attackers to run arbitrary code via returnUrl parameter in a crafted GET request.
CVE-2022-38247
- EPSS 34.27%
- Veröffentlicht 07.09.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 07:16:07
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Settings page under the Admin panel.
CVE-2022-38248
- EPSS 33.52%
- Veröffentlicht 07.09.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 07:16:07
Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.
CVE-2022-38249
- EPSS 33.52%
- Veröffentlicht 07.09.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 07:16:07
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4.
CVE-2022-38250
- EPSS 43.95%
- Veröffentlicht 07.09.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 07:16:07
Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.
CVE-2022-38251
- EPSS 36.1%
- Veröffentlicht 07.09.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 07:16:07
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Performance Settings page under the Admin panel.
CVE-2022-38254
- EPSS 33.52%
- Veröffentlicht 07.09.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 07:16:07
Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5.
CVE-2022-29269
- EPSS 5.09%
- Veröffentlicht 29.06.2022 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:58:50
In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.
CVE-2022-29270
- EPSS 0.54%
- Veröffentlicht 29.06.2022 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:58:50
In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address.
CVE-2022-29271
- EPSS 0.54%
- Veröffentlicht 29.06.2022 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:58:50
In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.