Impact
Nagios Core 4.5.13 and earlier, and Nagios XI 2026R1.6 and earlier, contain a DOM‑based cross‑site scripting flaw in jsonquery.js where unencoded JSON string values that reside in the database are injected directly into the DOM without sanitization. An attacker can embed malicious JavaScript that executes in a victim’s browser when a page using these values is rendered, enabling actions such as session hijacking, credential theft, or other browser‑based compromises.
Affected Systems
Nagios Enterprises, LLC’s Nagios Core version prior to 4.5.14 and Nagios XI prior to release 2026R1.7 are affected. The vulnerability is limited to the jsonquery.js component in those releases; later versions have the issue resolved.
Risk and Exploitability
The CVSS base score is 5.1, indicating moderate severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to supply a stored JSON value that is later rendered by jsonquery.js on a page viewed by a user. The attack is browser‑centric; it does not provide server‑side code execution but allows the injected script to run with the victim’s privileges, potentially compromising session data or other sensitive information.
OpenCVE Enrichment