Cross-Site Scripting Vulnerability in Nagios Log Server by Nagios
CVE-2020-25385
6.1MEDIUM
What is CVE-2020-25385?
Nagios Log Server version 2.1.7 is prone to a cross-site scripting (XSS) vulnerability, specifically in the create_snapshot functionality. This vulnerability arises from improper validation of user input via the snapshot_name parameter. When users interact with a malicious link or third-party web page, they may unintentionally execute scripts in their browsers, resulting in potential data theft or unauthorized actions. It's critical for users of this version to be aware of this risk and to apply security best practices when handling external links.
References
EPSS Score
37% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved