Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the background color settings in Dashboards. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
Advisories

No advisories yet.

Fixes

Solution

Nagios addresses this vulnerability as "Fixed XSS security vulnerability in background color in Dashboards."


Workaround

No workaround given by the vendor.

History

Thu, 30 Oct 2025 22:00:00 +0000

Type Values Removed Values Added
Description Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the background color settings in Dashboards. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
Title Nagios XI < 5.7.2 XSS via Dashboard Background Color Setting
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-10-30T21:51:46.256Z

Reserved: 2025-10-30T14:33:17.563Z

Link: CVE-2020-36864

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-30T22:15:39.290

Modified: 2025-10-30T22:15:39.290

Link: CVE-2020-36864

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.