Vulnerability record · CVE-2020-10821 · published 22 March 2020
CVE-2020-10821: Nagios XI theme parameter reflected XSS in account/main.php
Nagios · Nagios Xi
Nagios XI 5.6.11 does not properly sanitize the theme parameter in account/main.php, allowing reflected cross-site scripting. An attacker who can get a privileged, authenticated user to load a crafted URL can execute script in that user's browser session.
Description
Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityRequires high privileges and user interaction, limiting exploitation, but public exploit code and a very high EPSS score raise the risk for exposed Nagios XI instances.
What it is
Nagios XI 5.6.11 does not properly sanitize the theme parameter in account/main.php, allowing reflected cross-site scripting. An attacker who can get a privileged, authenticated user to load a crafted URL can execute script in that user's browser session.
Impact
An attacker can run arbitrary JavaScript in the context of a logged-in Nagios XI administrator, enabling session theft, credential capture, or actions performed as the victim. The CVSS scope change (S:C) means impact can extend beyond the vulnerable component.
Attack surface
Reached over the network via a crafted URL to account/main.php with a malicious theme parameter. The vector requires high privileges (PR:H) and user interaction (UI:R), so the attacker needs a valid high-privilege account or must lure an authenticated admin into clicking a link.
Exploitation
Not listed in CISA KEV. EPSS is high (0.71125, 99.4th percentile), and both references are tagged Exploit, indicating public proof-of-concept code exists.
What to do
- Upgrade Nagios XI past 5.6.11 to a release that fixes the theme parameter XSS.
- If immediate upgrade is not possible, restrict access to the Nagios XI web interface to trusted networks or VPN.
- Encode or reject untrusted input in the theme parameter and apply output encoding on account/main.php.
- Deploy a WAF rule to block script payloads in the theme parameter.
- Enforce least privilege so few accounts hold the high privileges needed to reach the vulnerable page.
Detection
- Search web logs for requests to account/main.php with script-like content in the theme parameter.
- Monitor for anomalous or unexpected JavaScript execution and outbound requests from admin browser sessions.
- Alert on repeated access to account/main.php with unusual theme values from a single source.
- Review Nagios XI admin account activity for session anomalies or unauthorized configuration changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://code610.blogspot.com/2020/03/nagios-5611-xssd.html | ExploitThird Party Advisory |
| https://code610.blogspot.com/2020/03/nagios-5611-xssd.html | ExploitThird Party Advisory |
Track CVE-2020-10821 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-10821), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.