VYPR
Medium severity4.8NVD Advisory· Published Oct 30, 2025· Updated Jun 17, 2026

CVE-2023-53689

CVE-2023-53689

Description

Nagios Fusion versions prior to 4.2.0 contain a reflected cross-site scripting (XSS) vulnerability in the license key configuration flow that can result in execution of attacker-controlled script in the browser of a user who follows a crafted URL. While the application server itself is not directly corrupted by the reflected XSS, the resulting browser compromise can lead to credential/session theft and unauthorized administrative actions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Nagios/Fusion3 versions
    cpe:2.3:a:nagios:fusion:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:nagios:fusion:*:*:*:*:*:*:*:*range: <4.2.0
    • (no CPE)range: <4.2.0
    • (no CPE)range: 0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.