PT-2025-44495 · Nagios · Nagios Log Server

Published

2023-12-05

·

Updated

2025-10-31

·

CVE-2023-7323

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Nagios Log Server versions prior to 2024R1
Description Nagios Log Server versions prior to 2024R1 are susceptible to cross-site scripting (XSS) through the Create User function. Insufficient validation or escaping of user-supplied input could allow an attacker to inject and execute arbitrary script within a victim’s browser.
Recommendations Update to Nagios Log Server version 2024R1 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2026-00273
CVE-2023-7323

Affected Products

Nagios Log Server