CVE-2020-27988
CVE-2020-27988 is a Cross-site Scripting (XSS) vulnerability. EPSS puts its 30-day exploitation probability at 91.3% (100th percentile). No vendor fix is recorded yet; mitigation options are listed below.
Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
Description
Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).
Affected Products
nagios xinagiosDetection & mitigation playbook
VulnerabilityDetect
Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).
Remediation status
No fixed release is recorded for CVE-2020-27988 yet. Track the upstream advisory, and apply the exposure-reduction steps below in the meantime.
Mitigate without a patch
Escape or sanitise the affected output on the server side rather than relying on client-side filtering, and add a Content-Security-Policy that blocks inline script execution so injected markup cannot run even if it reaches the page.
Frequently Asked Questions
Is CVE-2020-27988 in your dependencies?
Find it across , including transitive dependencies.