← Vulnerability feed

Vulnerability record · CVE-2018-15712 · published 14 November 2018

CVE-2018-15712: Nagios XI api_tool.php host parameter reflected XSS

Nagios · Nagios Xi

Nagios XI 5.5.6 reflects the host parameter in api_tool.php without proper output encoding, allowing reflected cross-site scripting. Because the endpoint is reachable without authentication, an attacker can craft a link that runs script in a victim's browser in the context of the Nagios XI site.

6.1 CVSS 3.0 Medium EPSS 49% · top 1.2% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the host parameter in api_tool.php.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

medium priorityReflected XSS requires user interaction and yields limited direct impact, but unauthenticated reachability and public exploit code raise the practical risk.

What it is

Nagios XI 5.5.6 reflects the host parameter in api_tool.php without proper output encoding, allowing reflected cross-site scripting. Because the endpoint is reachable without authentication, an attacker can craft a link that runs script in a victim's browser in the context of the Nagios XI site.

Impact

An attacker can execute arbitrary script in a victim's browser session, potentially stealing session cookies or performing actions as the victim within Nagios XI. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.

Attack surface

Reached over the network via a crafted URL to api_tool.php with a malicious host parameter; no authentication is required, but the victim must click the link (UI:R).

Exploitation

Not listed in CISA KEV, but EPSS is high (0.48555, 98.8th percentile) and both references are tagged Exploit, indicating public exploit code exists.

What to do

  • Upgrade Nagios XI past 5.5.6 to a version that encodes the host parameter in api_tool.php.
  • If immediate upgrade is not possible, restrict network access to api_tool.php to trusted management networks.
  • Deploy a WAF rule to block script payloads in the host parameter of api_tool.php.
  • Enforce HttpOnly and Secure flags on Nagios XI session cookies to limit cookie theft.
  • Audit logs for requests to api_tool.php with suspicious host parameter values.

Detection

  • Search web/proxy logs for requests to api_tool.php with script tags or event handlers in the host parameter.
  • Alert on outbound or inline script content in responses from api_tool.php.
  • Monitor for unusual referrer or URL patterns containing encoded script in the host parameter.
  • Review Nagios XI access logs for repeated api_tool.php requests from a single source.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-15712 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-25296Nagios XI Windows WMI Config Wizard OS Command InjectionNagios XI 5.7.5 fails to sanitize authenticated user input in the windowswmi config wizard file, allowing OS command injection. Because the affected …KEVEPSS 72%analysed8.8CVE-2021-25297Nagios XI switch config wizard OS command injectionNagios XI 5.7.5 fails to sanitize authenticated user input in the switch configuration wizard file switch.inc.php, allowing OS command injection via …KEVEPSS 57%analysed8.8CVE-2021-25298Nagios XI cloud-vm config wizard OS command injectionNagios XI 5.7.5 fails to properly sanitize authenticated user input in /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php, all…KEVEPSS 75%analysed8.8CVE-2019-15949Nagios XI getprofile.sh command injection allows root code executionNagios XI before 5.6.6 runs the getprofile.sh script as root through a passwordless sudo entry when a system profile is downloaded. Because that scri…KEVEPSS 77%analysed9.8CVE-2024-24401Nagios XI monitoringwizard.php SQL injection allows remote code executionNagios XI 2024R1.01 contains a SQL injection flaw in the monitoringwizard.php component. A remote attacker can send a crafted payload that leads to a…EPSS 46%analysed9.8CVE-2024-24402Nagios xi improper privilege management vulnerabilityAn issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.EPSS 3.4%9.8CVE-2023-48085Nagios XI command_test.php remote code executionNagios XI before 5.11.3 contains a remote code execution flaw in the command_test.php component, classified as code injection (CWE-94). The CVSS 3.1 …EPSS 76%analysed9.8CVE-2023-48084Nagios xi sql injection vulnerabilityNagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.EPSS 34%

Source: NIST National Vulnerability Database (record CVE-2018-15712), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.