{"api_version":"1","generated_at":"2026-07-24T03:28:01+00:00","cve":"CVE-2021-35478","urls":{"html":"https://cve.report/CVE-2021-35478","api":"https://cve.report/api/cve/CVE-2021-35478.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-35478","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-35478"},"summary":{"title":"CVE-2021-35478","description":"Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filtering are affected. This affects users who open a crafted link or third-party web page.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-07-30 14:15:00","updated_at":"2022-02-10 17:05:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://research.nccgroup.com/2021/07/22/technical-advisory-stored-and-reflected-xss-vulnerability-in-nagios-log-server-cve-2021-35478cve-2021-35479/","name":"https://research.nccgroup.com/2021/07/22/technical-advisory-stored-and-reflected-xss-vulnerability-in-nagios-log-server-cve-2021-35478cve-2021-35479/","refsource":"MISC","tags":[],"title":"Technical Advisory: Stored and Reflected XSS Vulnerability in Nagios Log Server (CVE-2021-35478,CVE-2021-35479) – NCC Group Research","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://research.nccgroup.com/?research=Technical%20advisories","name":"https://research.nccgroup.com/?research=Technical%20advisories","refsource":"MISC","tags":[],"title":"NCC Group Research Blog | Making the world safer and more secure","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.nagios.com/downloads/nagios-log-server/change-log/","name":"https://www.nagios.com/downloads/nagios-log-server/change-log/","refsource":"MISC","tags":[],"title":"Nagios Log Server Change Log - Nagios","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-35478","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-35478","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"35478","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nagios","cpe5":"log_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"35478","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"naigos","cpe5":"nagios_log_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-35478","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filtering are affected. This affects users who open a crafted link or third-party web page."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://www.nagios.com/downloads/nagios-log-server/change-log/","refsource":"MISC","name":"https://www.nagios.com/downloads/nagios-log-server/change-log/"},{"url":"https://research.nccgroup.com/?research=Technical%20advisories","refsource":"MISC","name":"https://research.nccgroup.com/?research=Technical%20advisories"},{"refsource":"MISC","name":"https://research.nccgroup.com/2021/07/22/technical-advisory-stored-and-reflected-xss-vulnerability-in-nagios-log-server-cve-2021-35478cve-2021-35479/","url":"https://research.nccgroup.com/2021/07/22/technical-advisory-stored-and-reflected-xss-vulnerability-in-nagios-log-server-cve-2021-35478cve-2021-35479/"}]}},"nvd":{"publishedDate":"2021-07-30 14:15:00","lastModifiedDate":"2022-02-10 17:05:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.3,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.5},"severity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nagios:log_server:*:*:*:*:*:*:*:*","versionEndExcluding":"2.1.9","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"35478","Ordinal":"210975","Title":"CVE-2021-35478","CVE":"CVE-2021-35478","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"35478","Ordinal":"1","NoteData":"Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filtering are affected. This affects users who open a crafted link or third-party web page.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"35478","Ordinal":"2","NoteData":"2021-07-27","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"35478","Ordinal":"3","NoteData":"2021-07-27","Type":"Other","Title":"Modified"}]}}}