Technical Advisory: Stored and Reflected XSS Vulnerability in Nagios Log Server (CVE-2021-35478,CVE-2021-35479)
ID: e353a264-319a-59a6-8be2-41aac9d9582e
STIX ID: report--e353a264-319a-59a6-8be2-41aac9d9582e
Feed Name: NCC Research
Threat Score
Nagios Log Server 2.1.8 contains both reflected and stored XSS (CVE-2021-35478) in audit log and alert history parameters, enabling client-side script execution (e.g., cookie theft or redirects). Proof-of-concept GET and POST payloads are provided; vendor fixed the issue in 2.1.9 and a patch/release timeline is included.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
