First published: Tue Jul 27 2021(Updated: )
Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filtering are affected. This affects users who open a crafted link or third-party web page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Log Server | <2.1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-35478.
The severity of CVE-2021-35478 is medium with a CVSS score of 5.4.
The affected software is Nagios Log Server version up to and excluding 2.1.9.
The CWE ID for CVE-2021-35478 is CWE-79.
CVE-2021-35478 allows attackers to perform reflected XSS attacks by tricking users into opening a crafted link or visiting a third-party web page.