Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-1615-1 nagios3 security update
EUVD EUVD EUVD-2018-9981 Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T11:01:14.898Z

Reserved: 2018-10-11T00:00:00

Link: CVE-2018-18245

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-12-17T15:29:00.327

Modified: 2024-11-21T03:55:34.720

Link: CVE-2018-18245

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-12-12T00:00:00Z

Links: CVE-2018-18245 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses