N
agios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) and cross-site request forgery (CSRF) via the Hypermap Replay component. An attacker can submit crafted input that is not properly validated or escaped, allowing injection of malicious script that executes in the context of a victim's browser (XSS). Additionally, the component does not enforce sufficient anti-CSRF protections on state-changing operations, enabling an attacker to induce authenticated users to perform unwanted actions.
References
| Link | Resource |
|---|---|
| https://www.nagios.com/changelog/nagios-xi/ | Release Notes |
| https://www.nagios.com/products/security/#nagios-xi | Release Notes |
| https://www.vulncheck.com/advisories/nagios-xi-xss-and-csrf-via-hypermap-relay | Third Party Advisory |
Configurations
History
05 Nov 2025, 18:21
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
| References | () https://www.nagios.com/changelog/nagios-xi/ - Release Notes | |
| References | () https://www.nagios.com/products/security/#nagios-xi - Release Notes | |
| References | () https://www.vulncheck.com/advisories/nagios-xi-xss-and-csrf-via-hypermap-relay - Third Party Advisory | |
| First Time |
Nagios
Nagios nagios Xi |
30 Oct 2025, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-30 22:15
Updated : 2025-11-05 18:21
NVD link : CVE-2023-53688
Mitre link : CVE-2023-53688
CVE.ORG link : CVE-2023-53688
JSON object : View