CVE-2024-54959

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Feb 20, 2025
Updated: Feb 21, 2025
CWE ID 79

Summary

CVE-2024-54959 is a newly discovered vulnerability affecting Nagios XI 2024R1.2.2. An attacker can exploit this vulnerability through a Cross-Site Request Forgery (CSRF) attack, specifically targeting the Favorites component. Successful exploitation allows the attacker to execute POST-based Cross-Site Scripting (XSS) code on unsuspecting users' browsers. The vulnerability poses a significant risk, as it can lead to unauthorized actions and data theft. Users are strongly encouraged to update their Nagios XI installations to the latest version to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Nagios Core

Affected Vendors

  • Nagios Enterprises LLC