Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-40932

A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the login page which means the attacker is able to to steal plaintext credentials.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.02
EPSS Ranking 82.5%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2023-40932


Contact Us

Shodan ® - All rights reserved