PT-2025-44464 · Nagios · Nagios Log Server

Published

2020-04-22

·

Updated

2025-10-30

·

CVE-2020-36858

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Nagios Log Server versions prior to 2.1.6
Description Nagios Log Server versions prior to 2.1.6 contain cross-site scripting (XSS) issues through the web interface on the Create User, Edit User, and Manage Host Lists pages. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
Recommendations Update Nagios Log Server to version 2.1.6 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-16437
CVE-2020-36858

Affected Products

Nagios Log Server