CVE-2019-20139
30.12.2019, 15:15
In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulereport.php hour or frequency parameter. Any authenticated user can attack the admin user.
Vendor | Product | Version |
---|---|---|
nagios | nagios_xi | 5.6.9 |
𝑥
= Vulnerable software versions