First published: Thu Apr 08 2021(Updated: )
Self Authenticated XSS in Nagios Network Analyzer before 2.4.2 via the nagiosna/groups/queries page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Network Analyzer | <2.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28924 is a vulnerability in Nagios Network Analyzer before version 2.4.2 that allows for self-authenticated XSS via the nagiosna/groups/queries page.
CVE-2021-28924 has a severity level of medium with a CVSS score of 6.1.
CVE-2021-28924 affects Nagios Network Analyzer versions up to and excluding 2.4.3.
To fix CVE-2021-28924, it is recommended to update Nagios Network Analyzer to version 2.4.3 or later.
Yes, you can find more information about CVE-2021-28924 in the following references: [Medium article](https://medium.com/stolabs/issues-found-on-nagios-network-analyzer-2-4-2-50ec4ffb5e25) and [Nagios Network Analyzer change log](https://www.nagios.com/downloads/nagios-network-analyzer/change-log/).