Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) and cross-site request forgery (CSRF) via the Hypermap Replay component. An attacker can submit crafted input that is not properly validated or escaped, allowing injection of malicious script that executes in the context of a victim's browser (XSS). Additionally, the component does not enforce sufficient anti-CSRF protections on state-changing operations, enabling an attacker to induce authenticated users to perform unwanted actions.
Advisories

No advisories yet.

Fixes

Solution

Nagios addresses this vulnerability as "The Hypermap Replay component is vulnerable to a cross-site scripting attack and cross-site request forgery" and "Fixed a CSRF and XSS vulnerability in the hypermap replay component."


Workaround

No workaround given by the vendor.

History

Fri, 31 Oct 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Nagios
Nagios xi
Vendors & Products Nagios
Nagios xi

Thu, 30 Oct 2025 22:00:00 +0000

Type Values Removed Values Added
Description Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) and cross-site request forgery (CSRF) via the Hypermap Replay component. An attacker can submit crafted input that is not properly validated or escaped, allowing injection of malicious script that executes in the context of a victim's browser (XSS). Additionally, the component does not enforce sufficient anti-CSRF protections on state-changing operations, enabling an attacker to induce authenticated users to perform unwanted actions.
Title Nagios XI < 5.11.3 XSS & CSRF via Hypermap Replay
Weaknesses CWE-352
CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-10-30T21:47:42.470Z

Reserved: 2025-10-17T15:49:31.356Z

Link: CVE-2023-53688

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-30T22:15:42.487

Modified: 2025-10-30T22:15:42.487

Link: CVE-2023-53688

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-31T10:13:15Z