PoC Index

CVE-2019-20139

MEDIUM 5.4EPSS 26.1%

In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulereport.php hour or frequency parameter. Any authenticated user can attack the admin user.

CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
26.11% chance of exploitation in the next 30 days, 98th percentile
Published
2019-12-30
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related