
Cloud Vulnerability DB
A community-led vulnerabilities database
Nagios XI version 5.7.5 contains a cross-site scripting (XSS) vulnerability identified as CVE-2021-25299. The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input via the 'url=' parameter. This vulnerability was discovered and reported in February 2021 (CVE Details, Check Point).
The vulnerability is present in the SSH terminal web interface of Nagios XI 5.7.5, specifically in the sshterm.php file. The application fails to properly sanitize user input received through the 'url=' parameter, allowing attackers to inject arbitrary HTML and script code into the vulnerable web server (ConnectWise).
When successfully exploited, this vulnerability allows an attacker to steal session cookies from admin users or potentially chain it with other vulnerabilities to achieve remote command execution (RCE) on the Nagios XI server (CVE Details).
The vulnerability requires an admin user to click on a maliciously crafted URL. A proof-of-concept (PoC) exploit has been published on GitHub, demonstrating the vulnerability's exploitability (GitHub PoC).
Users should upgrade from Nagios XI 5.7.5 to a newer version that contains security fixes. The vulnerability has been addressed in subsequent releases (Nagios Versions).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."