CVE-2020-6586
MEDIUMNagios Log Server 2.1.3 - Stored Cross-Site Scripting via User Profile Name Field
Title source: llmDescription
Nagios Log Server 2.1.3 allows XSS by visiting /profile and entering a crafted name field that is mishandled on the /admin/users page. Any malicious user with limited access can store an XSS payload in his Name. When any admin views this, the XSS is triggered.
References (3)
Core 3
Core References
Product x_refsource_misc
https://www.nagios.com/products/nagios-log-server/
Various Sources x_refsource_misc
https://medium.com/%40fixitt6/multiple-vulnerabilities-in-nagios-log-server-2-1-3-af7c160edc60
Release Notes, Vendor Advisory x_refsource_misc
https://assets.nagios.com/downloads/nagios-log-server/CHANGES.TXT
Scores
CVSS v3
5.4
EPSS
0.0733
EPSS Percentile
91.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
nagios/nagios
2.1.3
Published
Mar 16, 2020
Tracked Since
Feb 18, 2026