Nagios XI versions prior to 2012R1.6 contain a reflected cross-site scripting (XSS) vulnerability in the dashboard dashlet AJAX load functionality. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
| Software | From | Fixed in |
|---|---|---|
| nagios / nagios_xi | - | 2011.x |
| nagios / nagios_xi | 2012-r1.0 | 2012-r1.0.x |
| nagios / nagios_xi | 2012-r1.1 | 2012-r1.1.x |
| nagios / nagios_xi | 2012-r1.2 | 2012-r1.2.x |
| nagios / nagios_xi | 2012-r1.3 | 2012-r1.3.x |
| nagios / nagios_xi | 2012-r1.4 | 2012-r1.4.x |
| nagios / nagios_xi | 2012-r1.5 | 2012-r1.5.x |