← Vulnerability feed

Vulnerability record · CVE-2020-10819 · published 22 March 2020

CVE-2020-10819: Nagios XI LDAP AD integration username parameter stored XSS

Nagios · Nagios Xi

Nagios XI 5.6.11 does not properly sanitize the username parameter in includes/components/ldap_ad_integration/, allowing cross-site scripting. A user with the required privileges can inject script that runs in the context of other users viewing the affected page, which matters because Nagios XI is a monitoring console often holding broad infrastructure access.

4.8 CVSS 3.1 Medium EPSS 71% · top 0.6% CWE-79 · Cross-site scripting
4.8CVSS 3.1 base score, v2 3.5
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ username parameter.

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

medium priorityRequires high privileges and user interaction, but public exploit code and a very high EPSS score raise the practical risk.

What it is

Nagios XI 5.6.11 does not properly sanitize the username parameter in includes/components/ldap_ad_integration/, allowing cross-site scripting. A user with the required privileges can inject script that runs in the context of other users viewing the affected page, which matters because Nagios XI is a monitoring console often holding broad infrastructure access.

Impact

An attacker can execute arbitrary script in a victim's browser session, potentially stealing session cookies or performing actions as the victim within the Nagios XI interface. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.

Attack surface

Reached over the network through the LDAP AD integration component; the vector requires high privileges (PR:H) and user interaction (UI:R), so an authenticated high-privilege user must be induced to view the crafted input.

Exploitation

Not listed in CISA KEV, but EPSS is 0.71333 (99.4th percentile) and both references are tagged Exploit and Third Party Advisory, indicating public exploit code exists.

What to do

  • Upgrade Nagios XI to a version later than 5.6.11 that fixes the LDAP AD integration XSS.
  • Restrict access to the LDAP AD integration component to trusted administrators only.
  • Apply input validation and output encoding to the username parameter if patching is delayed.
  • Deploy a WAF rule to block script payloads in the ldap_ad_integration username parameter.

Detection

  • Search Nagios XI web logs for requests to includes/components/ldap_ad_integration/ containing script tags or encoded script in the username parameter.
  • Monitor for anomalous or unexpected script content stored in Nagios XI configuration or user profile fields.
  • Review authentication and session logs for suspicious activity by high-privilege accounts around the LDAP AD integration page.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-10819 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-25296Nagios XI Windows WMI Config Wizard OS Command InjectionNagios XI 5.7.5 fails to sanitize authenticated user input in the windowswmi config wizard file, allowing OS command injection. Because the affected …KEVEPSS 72%analysed8.8CVE-2021-25297Nagios XI switch config wizard OS command injectionNagios XI 5.7.5 fails to sanitize authenticated user input in the switch configuration wizard file switch.inc.php, allowing OS command injection via …KEVEPSS 57%analysed8.8CVE-2021-25298Nagios XI cloud-vm config wizard OS command injectionNagios XI 5.7.5 fails to properly sanitize authenticated user input in /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php, all…KEVEPSS 75%analysed8.8CVE-2019-15949Nagios XI getprofile.sh command injection allows root code executionNagios XI before 5.6.6 runs the getprofile.sh script as root through a passwordless sudo entry when a system profile is downloaded. Because that scri…KEVEPSS 77%analysed9.8CVE-2024-24401Nagios XI monitoringwizard.php SQL injection allows remote code executionNagios XI 2024R1.01 contains a SQL injection flaw in the monitoringwizard.php component. A remote attacker can send a crafted payload that leads to a…EPSS 46%analysed9.8CVE-2024-24402Nagios xi improper privilege management vulnerabilityAn issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.EPSS 3.4%9.8CVE-2023-48085Nagios XI command_test.php remote code executionNagios XI before 5.11.3 contains a remote code execution flaw in the command_test.php component, classified as code injection (CWE-94). The CVSS 3.1 …EPSS 76%analysed9.8CVE-2023-48084Nagios xi sql injection vulnerabilityNagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.EPSS 34%

Source: NIST National Vulnerability Database (record CVE-2020-10819), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.