Vulnerability record · CVE-2021-35478 · published 30 July 2021
CVE-2021-35478: Nagios Log Server reflected XSS in alert history and audit log filters
Nagios · Log Server
Nagios Log Server before 2.1.9 reflects unfiltered input in the dropdown box used for alert history and audit log filtering, allowing reflected cross-site scripting. Because all filter parameters are affected, an attacker can craft a link or third-party page that executes script in a victim's browser within the application context.
Description
Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filtering are affected. This affects users who open a crafted link or third-party web page.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityReflected XSS requires user interaction and low privileges, but public exploit detail and a very high EPSS score raise the practical risk.
What it is
Nagios Log Server before 2.1.9 reflects unfiltered input in the dropdown box used for alert history and audit log filtering, allowing reflected cross-site scripting. Because all filter parameters are affected, an attacker can craft a link or third-party page that executes script in a victim's browser within the application context.
Impact
An attacker can run arbitrary script in the session of an authenticated Nagios Log Server user, enabling theft of session data or actions performed as that user. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.
Attack surface
Reached over the network through crafted URLs or third-party web pages that supply malicious filter parameters; the CVSS vector requires low privileges (PR:L) and user interaction (UI:R), so a victim must open the crafted link or page.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is very high (0.766, 99.5th percentile) and a reference is tagged Exploit, indicating public exploit detail exists.
What to do
- Upgrade Nagios Log Server to 2.1.9 or later per the vendor change log.
- If immediate upgrade is not possible, restrict access to the alert history and audit log interfaces to trusted networks and users.
- Encode or validate all filter parameters server-side and apply a strict Content-Security-Policy to limit script execution.
- Train users not to open unsolicited links to Nagios Log Server filter pages.
- Review logs for suspicious filter parameter values reaching the alert history and audit log endpoints.
Detection
- Search web logs for encoded script payloads or HTML tags in alert history and audit log filter parameters.
- Alert on requests containing script, onerror, or javascript: patterns in query strings to Nagios Log Server endpoints.
- Monitor for unusual outbound requests or session anomalies from authenticated Nagios Log Server users following filter page access.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://research.nccgroup.com/2021/07/22/technical-advisory-stored-and-reflected-xss-vulnerability-in-nagios-log-server- | ExploitThird Party Advisory |
| https://research.nccgroup.com/?research=Technical%20advisories | Third Party Advisory |
| https://www.nagios.com/downloads/nagios-log-server/change-log/ | Release NotesVendor Advisory |
| https://research.nccgroup.com/2021/07/22/technical-advisory-stored-and-reflected-xss-vulnerability-in-nagios-log-server- | ExploitThird Party Advisory |
| https://research.nccgroup.com/?research=Technical%20advisories | Third Party Advisory |
| https://www.nagios.com/downloads/nagios-log-server/change-log/ | Release NotesVendor Advisory |
Track CVE-2021-35478 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-35478), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.