First published: Wed Jan 20 2021(Updated: )
Nagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/create_snapshot through the snapshot_name parameter, which may impact users who open a maliciously crafted link or third-party web page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Log Server | <=2.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25385 is a cross-site scripting (XSS) vulnerability in Nagios Log Server 2.1.7.
CVE-2020-25385 may impact users who open a maliciously crafted link or third-party web page.
CVE-2020-25385 can be exploited by manipulating the snapshot_name parameter in /nagioslogserver/configure/create_snapshot.
CVE-2020-25385 has a severity rating of 6.1 (Medium).
At the moment, there is no official fix available for CVE-2020-25385. It is recommended to follow best security practices and avoid opening suspicious links or visiting malicious websites.