GHSA-m927-w885-wph8MediumCVSS 5.4
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site...
🔗 CVE IDs covered (1)
📋 Description
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string values reflected from stored fields are inserted into the DOM without sanitization, allowing attackers to run arbitrary JavaScript in the victim's browser.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-48552
- https://github.com/NagiosEnterprises/nagioscore/blob/master/Changelog
- https://www.nagios.com/security-disclosures/nagios-core
- https://www.vulncheck.com/advisories/nagios-core-xi-dom-based-xss-via-jsonquery-js
- https://github.com/advisories/GHSA-m927-w885-wph8