PoC Index

CVE-2021-35479

MEDIUM 5.4EPSS 13.2%

Nagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log function through the affected pp parameter. This affects users who open a crafted link or third-party web page.

CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
EPSS
13.15% chance of exploitation in the next 30 days, 96th percentile
Published
2021-07-27
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related