PoC Index

CVE-2021-35478

MEDIUM 5.4EPSS 76.6%

Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filtering are affected. This affects users who open a crafted link or third-party web page.

CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
76.62% chance of exploitation in the next 30 days, 100th percentile
Published
2021-07-27
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related