CVE-2025-56432

A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to execute arbitrary JavaScript in the context of a logged-in user's session via a specially crafted URL. The issue resides in a web component responsible for rendering performance-related data.
References
Link Resource
http://nagios.com Product
https://www.nagios.com/changelog/ Release Notes
Configurations

Configuration 1 (hide)

cpe:2.3:a:nagios:nagios_xi:2024:r2:*:*:*:*:*:*

History

No history.

Information

Published : 2025-08-26 16:15

Updated : 2025-09-09 18:56


NVD link : CVE-2025-56432

Mitre link : CVE-2025-56432

CVE.ORG link : CVE-2025-56432


JSON object : View

Products Affected

nagios

  • nagios_xi
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')