First published: Thu Jul 30 2020(Updated: )
A Stored XSS vulnerability exists in Nagios Log Server before 2.1.7 via the Notification Methods -> Email Users menu.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Log Server | <2.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-16157 is medium with a CVSS score of 5.4.
The Stored XSS vulnerability in Nagios Log Server before 2.1.7 occurs via the Notification Methods -> Email Users menu.
Nagios Log Server versions up to but excluding 2.1.7 are affected by CVE-2020-16157.
Yes, there are public references available for CVE-2020-16157. You can find them at the following links: http://packetstormsecurity.com/files/158992/Nagios-Log-Server-2.1.6-Cross-Site-Scripting.html, https://www.getastra.com/blog/911/stored-xss-vulnerability-nagios-log-server/, https://www.jinsonvarghese.com/stored-xss-vulnerability-in-nagios-log-server/
Yes, to fix CVE-2020-16157, you need to update Nagios Log Server to version 2.1.7 or later.