CVE-2021-28924: XSS
Self Authenticated XSS in Nagios Network Analyzer before 2.4.2 via the nagiosna/groups/queries page.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-28924?
CVE-2021-28924 is a vulnerability in Nagios Network Analyzer before version 2.4.2 that allows for self-authenticated XSS via the nagiosna/groups/queries page.
How severe is CVE-2021-28924?
CVE-2021-28924 has a severity level of medium with a CVSS score of 6.1.
How does CVE-2021-28924 affect Nagios Network Analyzer?
CVE-2021-28924 affects Nagios Network Analyzer versions up to and excluding 2.4.3.
How can I fix CVE-2021-28924 in Nagios Network Analyzer?
To fix CVE-2021-28924, it is recommended to update Nagios Network Analyzer to version 2.4.3 or later.
Is there any additional information available about CVE-2021-28924?
Yes, you can find more information about CVE-2021-28924 in the following references: [Medium article](https://medium.com/stolabs/issues-found-on-nagios-network-analyzer-2-4-2-50ec4ffb5e25) and [Nagios Network Analyzer change log](https://www.nagios.com/downloads/nagios-network-analyzer/change-log/).