Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fjw4-rpc3-849f

Опубликовано: 04 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 6.1

Описание

Nagios XI versions prior to 5.4.0 are vulnerable to cross-site scripting (XSS) via the jQuery Migrate library. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

Nagios XI versions prior to 5.4.0 are vulnerable to cross-site scripting (XSS) via the jQuery Migrate library. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

5.1 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

nvd
3 месяца назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a downstream effect of an already identified vulnerability, CVE-2012-6708.

CVSS3: 6.1
fstec
около 9 лет назад

Уязвимость библиотеки jQuery Migrate инструмента для мониторинга ИТ-инфраструктуры Nagios XI, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

5.1 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79