VYPR
Medium severity5.4NVD Advisory· Published Jun 19, 2019· Updated Jun 17, 2026

CVE-2018-17146

CVE-2018-17146

Description

A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript code within the auto login admin management page.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Nagios/XI2 versions
    cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*range: <5.5.4
    • (no CPE)range: <5.5.4
  • Nagios Enterprises/Nagios XIdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.