Impact
Nagios Core and Nagios XI allow a reflected cross‑site scripting flaw in cmd.cgi via the NagFormId parameter. An unauthenticated attacker can construct a malicious link that, when visited by an authenticated user, causes the user’s browser to execute arbitrary JavaScript. This flaw enables theft of session cookies, defacement of web pages, or execution of further client‑side attacks.
Affected Systems
Nagios Enterprises, LLC. sells Nagios Core and Nagios XI. The vulnerability affects all Nagios Core releases prior to version 4.5.14 and all Nagios XI releases prior to 2026R1.7.
Risk and Exploitability
The CVSS score is 5.1, indicating medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to craft a malicious link and rely on a victim who is logged into the system to click it; therefore the threat is primarily phishing or social‑engineering based. Given the lack of a known exploit, the immediate risk is moderate but definite, and the flaw is actionable by applying the vendor’s newer releases.
OpenCVE Enrichment