CVE-2024-54958

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
20/02/2025
Last modified:
01/07/2025

Description

Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts into the Tools interface, which are then stored and executed in the context of other users accessing the page.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nagios:nagios_xi:2024:r1.2.2:*:*:*:*:*:*


References to Advisories, Solutions, and Tools