Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing page" (404) page after following a link from another website. The vulnerable component, page-missing.php, fails to properly validate or escape user-supplied input, allowing an attacker to craft a malicious link that, when visited by a victim, executes arbitrary JavaScript in the victim’s browser within the Nagios XI domain.

Project Subscriptions

Vendors Products
Advisories

No advisories yet.

Fixes

Solution

Nagios addresses this vulnerability as "Nagios XI is vulnerable to a cross-site scripting (XSS) vulnerability when visiting the "missing page" page from another website" and "Fixed XSS in page-missing.php."


Workaround

No workaround given by the vendor.

History

Mon, 17 Nov 2025 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:nagios:nagios_xi:2024:*:*:*:*:*:*:*

Thu, 06 Nov 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Nagios nagios Xi
CPEs cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.0.1:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1.0.2:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:2024:r1:*:*:*:*:*:*
Vendors & Products Nagios nagios Xi
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Mon, 03 Nov 2025 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Nagios
Nagios xi
Vendors & Products Nagios
Nagios xi

Fri, 31 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Oct 2025 13:00:00 +0000

Type Values Removed Values Added
Description Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing page" (404) page after following a link from another website. The vulnerable component, page-missing.php, fails to properly validate or escape user-supplied input, allowing an attacker to craft a malicious link that, when visited by a victim, executes arbitrary JavaScript in the victim’s browser within the Nagios XI domain.
Title Nagios XI < 2024R1.1 XSS via Missing Page / 404
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-11-17T18:21:46.964Z

Reserved: 2025-10-22T15:49:48.292Z

Link: CVE-2024-13992

cve-icon Vulnrichment

Updated: 2025-10-31T14:12:52.400Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-31T13:15:33.057

Modified: 2025-11-06T18:12:02.937

Link: CVE-2024-13992

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-03T10:44:00Z

Weaknesses