CVE-2021-25299
Nagios XI 5.7.5 Remote Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal his/her session cookies or it can be chained with the previous bugs to get one-click remote command execution (RCE) on the Nagios XI server.
Nagios XI versión xi-5.7.5, esta afectada por una vulnerabilidad de tipo cross-site scripting (XSS). La vulnerabilidad se presenta en el archivo /usr/local/nagiosxi/html/admin/sshterm.php debido a un saneamiento inapropiado de la entrada controlada por el usuario. Una URL maliciosamente, cuando un usuario administrador hace clic en ella, puede ser usada para robar las cookies de su sesión o puede ser encadenada con los bugs previos para obtener una ejecución de comandos remota (RCE) con un solo clic en el servidor de Nagios XI
Nagios XI version 5.7.5 suffers from a cross site scripting and multiple remote code execution vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-18 CVE Reserved
- 2021-02-15 CVE Published
- 2021-02-26 First Exploit
- 2024-08-03 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://nagios.com | Product | |
https://assets.nagios.com/downloads/nagiosxi/versions.php | Product |
URL | Date | SRC |
---|
URL | Date | SRC |
---|