CVE-2021-35478

MEDIUM

Nagios Log Server < 2.1.9 - Reflected Cross-Site Scripting via Alert History and Audit Log Dropdown

Title source: llm
STIX 2.1

Description

Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filtering are affected. This affects users who open a crafted link or third-party web page.

Scores

CVSS v3 5.4
EPSS 0.4920
EPSS Percentile 97.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
nagios/log_server < 2.1.9
Published Jul 30, 2021
Tracked Since Feb 18, 2026