Vulnerability record · CVE-2018-15712 · published 14 November 2018
CVE-2018-15712: Nagios XI api_tool.php host parameter reflected XSS
Nagios · Nagios Xi
Nagios XI 5.5.6 reflects the host parameter in api_tool.php without proper output encoding, allowing reflected cross-site scripting. Because the endpoint is reachable without authentication, an attacker can craft a link that runs script in a victim's browser in the context of the Nagios XI site.
Description
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the host parameter in api_tool.php.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityReflected XSS requires user interaction and yields limited direct impact, but unauthenticated reachability and public exploit code raise the practical risk.
What it is
Nagios XI 5.5.6 reflects the host parameter in api_tool.php without proper output encoding, allowing reflected cross-site scripting. Because the endpoint is reachable without authentication, an attacker can craft a link that runs script in a victim's browser in the context of the Nagios XI site.
Impact
An attacker can execute arbitrary script in a victim's browser session, potentially stealing session cookies or performing actions as the victim within Nagios XI. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.
Attack surface
Reached over the network via a crafted URL to api_tool.php with a malicious host parameter; no authentication is required, but the victim must click the link (UI:R).
Exploitation
Not listed in CISA KEV, but EPSS is high (0.48555, 98.8th percentile) and both references are tagged Exploit, indicating public exploit code exists.
What to do
- Upgrade Nagios XI past 5.5.6 to a version that encodes the host parameter in api_tool.php.
- If immediate upgrade is not possible, restrict network access to api_tool.php to trusted management networks.
- Deploy a WAF rule to block script payloads in the host parameter of api_tool.php.
- Enforce HttpOnly and Secure flags on Nagios XI session cookies to limit cookie theft.
- Audit logs for requests to api_tool.php with suspicious host parameter values.
Detection
- Search web/proxy logs for requests to api_tool.php with script tags or event handlers in the host parameter.
- Alert on outbound or inline script content in responses from api_tool.php.
- Monitor for unusual referrer or URL patterns containing encoded script in the host parameter.
- Review Nagios XI access logs for repeated api_tool.php requests from a single source.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.tenable.com/security/research/tra-2018-37 | ExploitThird Party Advisory |
| https://www.tenable.com/security/research/tra-2018-37 | ExploitThird Party Advisory |
Track CVE-2018-15712 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-15712), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.