{"api_version":"1","generated_at":"2026-07-24T02:46:46+00:00","cve":"CVE-2021-35479","urls":{"html":"https://cve.report/CVE-2021-35479","api":"https://cve.report/api/cve/CVE-2021-35479.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-35479","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-35479"},"summary":{"title":"CVE-2021-35479","description":"Nagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log function through the affected pp parameter. This affects users who open a crafted link or third-party web page.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-07-30 14:15:00","updated_at":"2022-02-10 17:06:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://research.nccgroup.com/2021/07/22/technical-advisory-stored-and-reflected-xss-vulnerability-in-nagios-log-server-cve-2021-35478cve-2021-35479/","name":"https://research.nccgroup.com/2021/07/22/technical-advisory-stored-and-reflected-xss-vulnerability-in-nagios-log-server-cve-2021-35478cve-2021-35479/","refsource":"MISC","tags":[],"title":"Technical Advisory: Stored and Reflected XSS Vulnerability in Nagios Log Server (CVE-2021-35478,CVE-2021-35479) – NCC Group Research","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://research.nccgroup.com/?research=Technical%20advisories","name":"https://research.nccgroup.com/?research=Technical%20advisories","refsource":"MISC","tags":[],"title":"NCC Group Research Blog | Making the world safer and more secure","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.nagios.com/downloads/nagios-log-server/change-log/","name":"https://www.nagios.com/downloads/nagios-log-server/change-log/","refsource":"MISC","tags":[],"title":"Nagios Log Server Change Log - Nagios","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-35479","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-35479","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"35479","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nagios","cpe5":"log_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"35479","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"naigos","cpe5":"nagios_log_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-35479","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Nagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log function through the affected pp parameter. This affects users who open a crafted link or third-party web page."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://www.nagios.com/downloads/nagios-log-server/change-log/","refsource":"MISC","name":"https://www.nagios.com/downloads/nagios-log-server/change-log/"},{"url":"https://research.nccgroup.com/?research=Technical%20advisories","refsource":"MISC","name":"https://research.nccgroup.com/?research=Technical%20advisories"},{"refsource":"MISC","name":"https://research.nccgroup.com/2021/07/22/technical-advisory-stored-and-reflected-xss-vulnerability-in-nagios-log-server-cve-2021-35478cve-2021-35479/","url":"https://research.nccgroup.com/2021/07/22/technical-advisory-stored-and-reflected-xss-vulnerability-in-nagios-log-server-cve-2021-35478cve-2021-35479/"}]}},"nvd":{"publishedDate":"2021-07-30 14:15:00","lastModifiedDate":"2022-02-10 17:06:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.3,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.5},"severity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nagios:log_server:*:*:*:*:*:*:*:*","versionEndExcluding":"2.1.9","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"35479","Ordinal":"210976","Title":"CVE-2021-35479","CVE":"CVE-2021-35479","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"35479","Ordinal":"1","NoteData":"Nagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log function through the affected pp parameter. This affects users who open a crafted link or third-party web page.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"35479","Ordinal":"2","NoteData":"2021-07-27","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"35479","Ordinal":"3","NoteData":"2021-07-27","Type":"Other","Title":"Modified"}]}}}