Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · net nu 113 bronnen 1 kritiek 12 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2023-40932

MEDIUM · 5.4 CVSS Gepubliceerd: CWE-79

Beschrijving

A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the login page which means the attacker is able to to steal plaintext credentials.

Vendors

Nagios

Affected products

Nagios Xi

References