CVE-2021-25299
⚪ Do wiadomości
Cross-site scripting w Nagios XI pozwala na kradzież ciasteczek sesyjnych administratora.
CVSS
6.1
EPSS
97.7%
Exploit
poc
Vendor
nagios
Opis źródłowy (NVD)
Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal his/her session cookies or it can be chained with the previous bugs to get one-click remote command execution (RCE) on the Nagios XI server.
exploit rce xss
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 97.7% |
| Opublikowano (NVD) | 2021-02-15 13:15:12 UTC |
| Ostatnia modyfikacja (NVD) | 2026-07-09 01:16:47 UTC |
Referencje
- http://packetstormsecurity.com/files/161561/Nagios-XI-5.7.5-Remote-Code-Execution.html (cve@mitre.org) [Exploit, Third Party Advisory, VDB Entry]
- https://assets.nagios.com/downloads/nagiosxi/versions.php (cve@mitre.org) [Product]
- https://github.com/fs0c-sh/nagios-xi-5.7.5-bugs/blob/main/README.md (cve@mitre.org) [Exploit, Third Party Advisory]