CVE-2024-58272
30.10.2025, 22:15
Nagios Log Server versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerabilitywhere an attacker-supplied username containing JavaScript is stored and later rendered without proper encoding/escaping in admin or user-facing pages. When an authenticated victim loads the affected page, the browser executes the injected script in the victim's context.
Awaiting analysis
This vulnerability is currently awaiting analysis.