CVE-2021-35479
medium · 5.4Nagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log function through the affected pp parameter. This affects users who open a crafted link or third-party web page.
5.4
CVSS
13.2%
EPSS (exploit prob.)
96th
EPSS percentile
2021-07-30
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weaknesses
CWE-79
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| nagios | log_server | < 2.1.9 |
Check a specific version with /api/v1/cve/match.
References
- https://research.nccgroup.com/2021/07/22/technical-advisory-stored-and-reflected-xss-vulnerability-in-nagios-log-server-cve-2021-35478cve-2021-35479/
- https://research.nccgroup.com/?research=Technical%20advisories
- https://www.nagios.com/downloads/nagios-log-server/change-log/
- https://research.nccgroup.com/2021/07/22/technical-advisory-stored-and-reflected-xss-vulnerability-in-nagios-log-server-cve-2021-35478cve-2021-35479/
- https://research.nccgroup.com/?research=Technical%20advisories
- https://www.nagios.com/downloads/nagios-log-server/change-log/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-35479