Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email field.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://youtu.be/MvJuIkdTSQg | exploit |
https://www.nagios.com/changelog/#log-server | release notes |
https://www.exploit-db.com/exploits/52117 | exploit third party advisory |