Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of xiwindow variables used to build permalinks in the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
| Software | From | Fixed in |
|---|---|---|
| nagios / nagios_xi | - | 2009.x |
| nagios / nagios_xi | 2011-r1 | 2011-r1.x |
| nagios / nagios_xi | 2011-r1.1 | 2011-r1.1.x |
| nagios / nagios_xi | 2011-r1.2 | 2011-r1.2.x |
| nagios / nagios_xi | 2011-r1.3 | 2011-r1.3.x |
| nagios / nagios_xi | 2011-r1.4 | 2011-r1.4.x |
| nagios / nagios_xi | 2011-r1.5 | 2011-r1.5.x |
| nagios / nagios_xi | 2011-r1.6 | 2011-r1.6.x |
| nagios / nagios_xi | 2011-r1.7 | 2011-r1.7.x |
| nagios / nagios_xi | 2011-r1.8 | 2011-r1.8.x |