---
id: CVE-2021-37223
title: >-
  Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery
  (SSRF) vulnerability in schedulereport.php
summary: >-
  Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery
  (SSRF) vulnerability in schedulereport.php. Any authenticated user can create
  scheduled reports containing PDF screenshots of any view in the NagiosXI
  applicatio…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-918
vendor: nagios
product: nagios_xi
affected:
  - nagios_xi <= 5.8.4
published: '2021-10-05'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-37223'
references:
  - url: 'https://www.nagios.com/downloads/nagios-xi/change-log/'
    label: cve@mitre.org
  - url: 'http://nagios.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.nagios.com/downloads/nagios-xi/change-log/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.04978
epssPercentile: 0.91893
ingestedAt: '2026-07-06T17:03:23.587Z'
---

## Overview

Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. Any authenticated user can create scheduled reports containing PDF screenshots of any view in the NagiosXI application. Due to lack of input sanitisation, the target page can be replaced with an SSRF payload to access internal resources or disclose local system files.

## Affected

- `nagios_xi <= 5.8.4`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
