Impact
An open redirect flaw in the twilio_ajax_handler.php script of Nagios XI allows an attacker to force a user to visit a malicious site by supplying a crafted redirect URL. The vulnerability is classified as CWE‑601. Based on the description, it is inferred that this redirect can be used to trick users into clicking malicious links, trusted interface.
Affected Systems
Nagios XI systems running any version before 5.9.3 are affected. The vulnerability exists in the twilio_ajax_handler.php component of Nagios XI.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity, and the EPSS score of <1% reflects a very low exploitation probability. Based on the description, it is inferred that the flaw does not require authentication or elevated privileges, and the attack path relies on user interaction to trigger the redirect. The vulnerability is not listed in the CISA KEV catalog, so no known active exploitation is documented.
OpenCVE Enrichment