PT-2025-44508 · Nagios · Nagios Log Server

Published

2025-10-30

·

Updated

2025-10-31

·

CVE-2024-58272

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nagios Log Server versions prior to 2024R1
Description The software contains a stored cross-site scripting (XSS) issue. An attacker can inject JavaScript code through a manipulated username that is stored and then displayed on admin or user-facing pages without proper encoding or escaping. When an authenticated user accesses the affected page, the injected script executes within their browser session.
Recommendations Update to Nagios Log Server version 2024R1 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-58272

Affected Products

Nagios Log Server