Metrics
Affected Vendors & Products
No advisories yet.
Solution
Nagios addresses this vulnerability as "Nagios XI 2024R1.1.1 and earlier may be vulnerable to a reflected XSS in its login page when using older browsers" (within the "Security Disclosures" site) and it's unclear where or if it's addressed within the changelog.
Workaround
No workaround given by the vendor.
Fri, 31 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Fri, 31 Oct 2025 10:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Nagios Nagios xi | |
| Vendors & Products | Nagios Nagios xi | 
Thu, 30 Oct 2025 22:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) via the login page when accessed with older web browsers. Insufficient validation or escaping of user-supplied input reflected by the login page can allow an attacker to craft a malicious link that, when visited by a victim, executes arbitrary JavaScript in the victim’s browser within the Nagios XI origin. The issue is observable under legacy browser behaviors; modern browsers may mitigate some vectors. | |
| Title | Nagios XI < 2024R1.1.2 Reflected XSS via Login Page on Older Browsers | |
| Weaknesses | CWE-79 | |
| References |  | |
| Metrics | cvssV4_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-10-31T13:23:45.427Z
Reserved: 2025-10-22T15:52:40.870Z
Link: CVE-2024-13993
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-10-31T13:04:25.657Z
 NVD
                        NVD
                    Status : Received
Published: 2025-10-30T22:15:44.623
Modified: 2025-10-30T22:15:44.623
Link: CVE-2024-13993
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    Updated: 2025-10-31T10:13:11Z