PT-2025-44539 · Nagios · Nagios Xi

CVE-2016-15051

·

Published

2025-10-30

·

Updated

2025-10-30

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 5.2.4
Description The Reports interface is susceptible to cross-site scripting (XSS), a flaw where malicious scripts are injected into trusted websites. This occurs due to insufficient validation or escaping of user-supplied input within the startdate and enddate fields, potentially allowing an attacker to execute arbitrary scripts in the victim's browser.
Recommendations Update to version 5.2.4 or later. As a temporary workaround, restrict access to the Reports interface or avoid using the startdate and enddate fields until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-15051

Affected Products

Nagios Xi