CVE-2021-35478
Summary
| CVE | CVE-2021-35478 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-30 14:15:00 UTC |
| Updated | 2022-02-10 17:05:00 UTC |
| Description | Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filtering are affected. This affects users who open a crafted link or third-party web page. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nagios | Log Server | All | All | All | All |
| Application | Naigos | Nagios Log Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Technical Advisory: Stored and Reflected XSS Vulnerability in Nagios Log Server (CVE-2021-35478,CVE-2021-35479) – NCC Group Research | MISC | research.nccgroup.com | |
| NCC Group Research Blog | Making the world safer and more secure | MISC | research.nccgroup.com | |
| Nagios Log Server Change Log - Nagios | MISC | www.nagios.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.