AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-40932

MEDIUM · CVSS 5.4 EPSS 0.92%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-09-19 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.4. It affects Java. Exploitation may require the attacker to be authenticated.

CVE
CVE-2023-40932
Severity
MEDIUM
CVSS
5.4
EPSS
0.92%
Java

Original NVD Description

A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the login page which means the attacker is able to to steal plaintext credentials.

Related CVEs

Other vulnerabilities affecting the same vendor(s)