S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-25299 Scanner

CVE-2021-25299 scanner - Cross-Site Scripting (XSS) vulnerability in Nagios XI

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-25299
6.1
CVSS

Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal his/her session cookies or it can be chained with the previous bugs to get one-click remote command execution (RCE) on the Nagios XI server.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Nagios XI is a powerful monitoring system designed to provide complete visibility into an organization's IT infrastructure. This tool is widely used by network and system administrators to monitor network devices, servers, applications, services, and remote systems. The Nagios XI version xi-5.7.5 is one of the latest versions of this software that provides a comprehensive set of features to monitor all aspects of IT infrastructure.

Recently, a serious vulnerability named CVE-2021-25299 has been reported in the Nagios XI version xi-5.7.5. This vulnerability allows an attacker to execute cross-site scripting (XSS) attacks on the server. The issue arises because the system fails to sanitize user-controlled input properly. Therefore, a malicious attacker could take advantage of this vulnerability to inject XSS payloads and steal the admin user's credentials or execute remote command execution (RCE) on the Nagios XI server.

This vulnerability can lead to severe consequences for organizations that use Nagios XI, including data loss or theft, business disruption, and financial losses. An attacker could exploit this flaw to inject malicious code that could damage the server or steal sensitive information from the system. An attacker could also use the stolen admin credentials to gain unauthorized access to the system and carry out further attacks.

In conclusion, Nagios XI is one of the most popular and widely used IT infrastructure monitoring tools. The vulnerability detected in Nagios XI version xi-5.7.5, CVE-2021-25299, poses a significant threat to organizations that use this software. However, Nagios XI users can protect their assets by taking precautions and updating their software to the latest version. Additionally, with the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets and take steps to protect themselves from cyber threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, Nagios XI users must update their software to the latest version and take the following precautions:

  • Implement strict access controls: Ensure that access to the Nagios XI server is limited to authorized personnel and that users only have access to the resources they need.
  • Enforce strong passwords: Ensure that users choose strong, unique passwords that are challenging to guess.
  • Monitor for suspicious activity: Implement a system that watches for any suspicious activity on the system and takes action immediately.
  • Keep the system up-to-date: Ensure that the Nagios XI server and all of its components are up-to-date with the latest security patches and updates.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-25299 scanner - Cross-Site Scripting (XSS) vulnerability in Nagios XI | S4E