PT-2025-44508 · Nagios · Nagios Log Server
Published
2025-10-30
·
Updated
2025-10-31
·
CVE-2024-58272
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Nagios Log Server versions prior to 2024R1
Description
The software contains a stored cross-site scripting (XSS) issue. An attacker can inject JavaScript code through a manipulated
username that is stored and then displayed on admin or user-facing pages without proper encoding or escaping. When an authenticated user accesses the affected page, the injected script executes within their browser session.Recommendations
Update to Nagios Log Server version 2024R1 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nagios Log Server