Show plain JSON{"id": "CVE-2018-17146", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 3.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N", "authentication": "SINGLE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "LOW", "obtainAllPrivilege": false, "exploitabilityScore": 6.8, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "CHANGED", "version": "3.0", "baseScore": 5.4, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N", "integrityImpact": "LOW", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "LOW", "confidentialityImpact": "LOW"}, "impactScore": 2.7, "exploitabilityScore": 2.3}]}, "published": "2019-06-19T18:15:11.007", "references": [{"url": "https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT", "tags": ["Release Notes", "Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT", "tags": ["Release Notes", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-79"}]}], "descriptions": [{"lang": "en", "value": "A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript code within the auto login admin management page."}, {"lang": "es", "value": "Existe una vulnerabilidad de scripts entre sitios en Nagios XI antes de 5.5.4 a trav\u00e9s del par\u00e1metro 'name' dentro de la p\u00e1gina Informaci\u00f3n de cuenta. La explotaci\u00f3n de esta vulnerabilidad permite a un atacante ejecutar c\u00f3digo JavaScript arbitrario dentro de la p\u00e1gina de administraci\u00f3n de inicio de sesi\u00f3n autom\u00e1tico."}], "lastModified": "2024-11-21T03:53:57.477", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F391CD96-609F-4452-8712-368EB87754F6", "versionEndExcluding": "5.5.4"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}