CVE-2020-36862 Details
Description
Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local exporting tool. Crafted export requests could (1) inject script into exported/returned content due to insufficient output encoding (XSS), and (2) cause the server to fetch attacker-specified URLs (SSRF), potentially accessing internal network resources. An unauthenticated remote attacker can leverage these issues to execute script in a user's browser when the exported content is viewed and to disclose sensitive information reachable from the export server via SSRF.
A vulnerability allowing unauthenticated cross-site scripting (XSS) and server-side request forgery (SSRF) has been identified in Nagios XI versions prior to 5.6.11. This issue resides in the Highcharts local exporting tool, where exported content could be manipulated to inject scripts due to inadequate output encoding, creating an XSS risk. Additionally, the server could be tricked into fetching URLs specified by an attacker, potentially accessing internal resources, thereby exploiting the SSRF aspect of the vulnerability. When the exported content is viewed, the injected scripts would execute in the user's browser, while the SSRF component could be used to access sensitive information from the export server's internal network.
Users can upgrade to Nagios XI version 5.6.11 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 31, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.nagios.com/changelog/nagios-xi/ | [email protected] | Release Notes |
| https://www.vulncheck.com/advisories/nagios-xi-unauthenticated-xss-and-ssrf-via-highcharts | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nagios nagios xi | < 5.6.11 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 5, 2025 | Initial Analysis | [email protected] |
| Oct 30, 2025 | New CVE Received | [email protected] |