logo

Technical Advisory: Stored and Reflected XSS Vulnerability in Nagios Log Server (CVE-2021-35478,CVE-2021-35479)

ID: e353a264-319a-59a6-8be2-41aac9d9582e

STIX ID: report--e353a264-319a-59a6-8be2-41aac9d9582e

Feed Name: NCC Research

Threat Score
30/100

Date Published: 2025-12-02

Date Updated: 2026-08-01

ADMIRALTY:B6
...
...

Nagios Log Server 2.1.8 contains both reflected and stored XSS (CVE-2021-35478) in audit log and alert history parameters, enabling client-side script execution (e.g., cookie theft or redirects). Proof-of-concept GET and POST payloads are provided; vendor fixed the issue in 2.1.9 and a patch/release timeline is included.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.