CVE-2019-20139
In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulerepor
In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulereport.php hour or frequency parameter. Any authenticated user can attack the admin user.
MEDIUM · CVSS 5.4
EPSS 0.06306
Schedule remediation
- EPSS percentile: top 9% of all CVEs by exploitation likelihood
- Public exploit or PoC is available
Sigma rules0
YARA rules0