A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to execute arbitrary JavaScript in the context of a logged-in user's session via a specially crafted URL. The issue resides in a web component responsible for rendering performance-related data.
| Software | From | Fixed in |
|---|---|---|
| nagios / nagios_xi | 2024-r2 | 2024-r2.x |