Nagios Log Server 2.1.3 allows XSS by visiting /profile and entering a crafted name field that is mishandled on the /admin/users page. Any malicious user with limited access can store an XSS payload in his Name. When any admin views this, the XSS is triggered.
References
Configurations
History
21 Nov 2024, 05:36
Type | Values Removed | Values Added |
---|---|---|
References | () https://assets.nagios.com/downloads/nagios-log-server/CHANGES.TXT - Release Notes, Vendor Advisory | |
References | () https://medium.com/%40fixitt6/multiple-vulnerabilities-in-nagios-log-server-2-1-3-af7c160edc60 - | |
References | () https://www.nagios.com/products/nagios-log-server/ - Product |
07 Nov 2023, 03:24
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2020-03-16 16:15
Updated : 2024-11-21 05:36
NVD link : CVE-2020-6586
Mitre link : CVE-2020-6586
CVE.ORG link : CVE-2020-6586
JSON object : View
Products Affected
nagios
- nagios
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')