CVE-2014-4908: PNP4NAGIOS

Medium severity, CVSS 4.3. EPSS: 1.9% chance of exploitation in the next 30 days.

Multiple cross-site scripting (XSS) vulnerabilities in PNP4Nagios through 0.6.22 allow remote attackers to inject arbitrary web script or HTML via the URI used for reaching (1) share/pnp/application/views/kohana_error_page.php or (2) share/pnp/application/views/template.php, leading to improper handling within an http-equiv="refresh" META element.

Affected products

  • PNP4NAGIOS PNP4NAGIOS: up to and including 0.6.21; version 0.6.0 only; version 0.6.1 only; version 0.6.2 only; version 0.6.3 only; version 0.6.4 only; …

Published 2014-07-11. Last modified 2026-06-17.