SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-29269

In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.

MEDIUM 6.5EPSS 3.33%

Does this matter?

Lower severity and a low EPSS score (3.33%). Track it; it rarely justifies an emergency change on its own.

Description

In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
3.33% probability · 88th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
nagios/nagios xi
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.