Vulnerability record · CVE-2020-27988 · published 16 November 2020
CVE-2020-27988: Nagios XI Manage Users username field stored XSS
Nagios · Nagios Xi
Nagios XI before 5.7.5 is vulnerable to cross-site scripting in the Manage Users Username field. An authenticated user with permission to manage users can inject script that executes in the browser of another user viewing that page, which matters because Nagios XI is a monitoring console often holding privileged infrastructure access.
Description
Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityRequires authentication and user interaction and is rated medium by CVSS, but the high EPSS score and privileged monitoring context warrant prompt patching.
What it is
Nagios XI before 5.7.5 is vulnerable to cross-site scripting in the Manage Users Username field. An authenticated user with permission to manage users can inject script that executes in the browser of another user viewing that page, which matters because Nagios XI is a monitoring console often holding privileged infrastructure access.
Impact
An attacker can run script in a victim's authenticated session, potentially stealing session tokens or performing actions as that user. The CVSS scope change (S:C) indicates the impact can extend beyond the vulnerable component.
Attack surface
Reached over the network through the Manage Users interface; the vector requires low privileges (PR:L) and user interaction (UI:R), so an authenticated account able to set the Username field plus a victim viewing the affected page are needed.
Exploitation
Not listed in CISA KEV and no public exploit references are provided; EPSS is very high (0.913, 99.8th percentile), suggesting elevated predicted exploitation activity despite the absence of KEV or exploit tags.
What to do
- Upgrade Nagios XI to 5.7.5 or later, per the vendor change log.
- Restrict Manage Users permissions to the smallest set of trusted administrators.
- Encode or sanitize the Username field on input and output if patching is delayed.
- Deploy a content security policy and browser protections to limit script execution in the admin console.
Detection
- Review Nagios XI audit or web logs for unusual Username values containing script tags or event handlers.
- Monitor for anomalous authenticated sessions or actions in Manage Users following page views by other accounts.
- Alert on outbound requests or token use from admin browsers that do not match normal Nagios XI behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.nagios.com/downloads/nagios-xi/change-log/ | Release NotesVendor Advisory |
| https://www.nagios.com/downloads/nagios-xi/change-log/ | Release NotesVendor Advisory |
Track CVE-2020-27988 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-27988), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.