CVE-2024-54958

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Feb 20, 2025
Updated: Feb 21, 2025
CWE ID 79

Summary

CVE-2024-54958 is a newly disclosed Cross-Site Scripting (XSS) vulnerability affecting Nagios XI 2024R1.2.2. This issue allows an attacker to inject malicious scripts into the Tools page, which are then stored and executed in the context of other users accessing the interface. The vulnerability could potentially be exploited to steal sensitive information or conduct unauthorized actions on behalf of the victim. Users are strongly encouraged to upgrade to a patched version of Nagios XI as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Nagios Core

Affected Vendors

  • Nagios Enterprises LLC