CVE-2018-18245: Debian Linux

Medium severity, CVSS 5.4. EPSS: 2.5% chance of exploitation in the next 30 days.

Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Nagios Nagios Core: version 4.4.2 only

Published 2018-12-17. Last modified 2026-06-17.