Impact
An open redirect flaw in twilio_ajax_handler.php allows an attacker to force a user to visit a malicious site by supplying a crafted redirect URL. The weakness is CWE-601, which can be used for phishing or credential leakage by tricking users into following a link that appears to come from the trusted Nagios XI interface.
Affected Systems
Nagios XI systems running any version before 5.9.3 are affected. The vulnerability exists in the tjwilio_ajax_handler.php component of Nagios XI.
Risk and Exploitability
The CVSS score of 3.1 reflects the low severity of this flaw, and the EPSS score is not available, indicating limited known exploitation activity. The vulnerability does not require authentication or elevated privileges, and the attack path relies on user interaction to trigger the redirect. As it is not listed in CISA KEV, it is not known to be actively exploited in known campaigns.
OpenCVE Enrichment