Nagios Log Server
cpe:2.3:a:nagios:log_server:*:*:*:*:*:*:*
- < 2024R1
A stored cross-site scripting vulnerability has been identified in Nagios Log Server versions prior to 2024R1. This issue allows an attacker to inject a username containing JavaScript, which is then stored and later displayed without proper encoding or escaping on admin or user-facing pages. When an authenticated user accesses the affected page, the injected script is executed in their browser context.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the affected page.
Users are advised to upgrade to Nagios Log Server version 2024R1 or above.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.