CNNVD-202510-4154 Information

CNNVD ID

CNNVD-202510-4154

CVE-2020-36858

  • CNNVD Published: 2025-10-30

Description (Chinese)

Nagios Log Server是美国Nagios公司的一套集中式日志管理、监控和分析软件。 Nagios Log Server 2.1.6之前版本存在安全漏洞,该漏洞源于web界面中创建用户、编辑用户和管理主机列表页面未充分验证或转义用户输入,可能导致跨站脚本攻击。

Description (English)

Nagios Log Server is a centralized log management, monitoring and analysis software for the United States company Nagios. There was a security loophole in the previous version of Nagios Log Server 2.1.6, which originated from the fact that the creation of users, editing users and managing host list pages in the web interface were not sufficiently validated or converted to user input, which could result in a cross-site script attack.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Nagios

Published

2025-10-30

Last Modified

2026-02-24

References

https://www.nagios.com/changelog/nagios-log-server-2024r1/ https://www.vulncheck.com/advisories/nagios-log-server-xss-via-create-user-edit-user-and-manage-host-lists-pages

Patch

https://www.nagios.com/products/security/#log-server

Share on: