Security readout for executives and security teams
CVE-2014-4908 is a cross-site scripting issue in PNP4Nagios through 0.6.22. A crafted URI could cause script or HTML to be reflected through error or template views. Business risk is mainly compromise of users viewing the monitoring interface, not direct server takeover based on available sources. Exposure is likely limited to organizations still running PNP4Nagios through 0.6.22, especially where the web interface is reachable by untrusted users or the internet. Monitoring consoles often have privileged operators, so session theft or administrative action abuse may matter if XSS is triggered. Handle during normal vulnerability remediation unless the PNP4Nagios interface is internet-facing or used by privileged administrators from shared browsers. Escalate priority for exposed or unsupported deployments because monitoring systems can provide useful access for attackers. Mitigation focus: Inventory PNP4Nagios deployments and identify versions through 0.6.22.; Review upstream commits and vendor guidance for the maintained fix.; Upgrade to a release containing the referenced upstream fixes, if available..
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2014-4908 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/lingej/pnp4nagios/commit/cb925073edeeb97eb4ce61a86cdafccc9b87f9bbCVE reference · x_refsource_CONFIRM
- https://github.com/lingej/pnp4nagios/commit/e4a19768a5c5e5b1276caf3dd5bb721a540ec014CVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
