CVE-2020-25385: XSS
Nagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/createsnapshot through the snapshotname parameter, which may impact users who open a maliciously crafted link or third-party web page.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-25385?
CVE-2020-25385 is a cross-site scripting (XSS) vulnerability in Nagios Log Server 2.1.7.
What is the impact of CVE-2020-25385?
CVE-2020-25385 may impact users who open a maliciously crafted link or third-party web page.
How can CVE-2020-25385 be exploited?
CVE-2020-25385 can be exploited by manipulating the snapshot_name parameter in /nagioslogserver/configure/create_snapshot.
What is the severity of CVE-2020-25385?
CVE-2020-25385 has a severity rating of 6.1 (Medium).
Is there a fix for CVE-2020-25385?
At the moment, there is no official fix available for CVE-2020-25385. It is recommended to follow best security practices and avoid opening suspicious links or visiting malicious websites.