In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulereport.php hour or frequency parameter. Any authenticated user can attack the admin user.
| Software | From | Fixed in |
|---|---|---|
| nagios / nagios_xi | 5.6.9 | 5.6.9.x |