Show plain JSON{"id": "CVE-2021-35478", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 3.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N", "authentication": "SINGLE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "LOW", "obtainAllPrivilege": false, "exploitabilityScore": 6.8, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "CHANGED", "version": "3.1", "baseScore": 5.4, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N", "integrityImpact": "LOW", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "LOW", "confidentialityImpact": "LOW"}, "impactScore": 2.7, "exploitabilityScore": 2.3}]}, "published": "2021-07-30T14:15:17.917", "references": [{"url": "https://research.nccgroup.com/2021/07/22/technical-advisory-stored-and-reflected-xss-vulnerability-in-nagios-log-server-cve-2021-35478cve-2021-35479/", "tags": ["Exploit", "Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://research.nccgroup.com/?research=Technical%20advisories", "tags": ["Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://www.nagios.com/downloads/nagios-log-server/change-log/", "tags": ["Release Notes", "Vendor Advisory"], "source": "cve@mitre.org"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-79"}]}], "descriptions": [{"lang": "en", "value": "Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filtering are affected. This affects users who open a crafted link or third-party web page."}, {"lang": "es", "value": "Nagios Log Server versiones anteriores a 2.1.9, contiene una vulnerabilidad de tipo XSS Reflejado en el dropdown box de la funci\u00f3n alert history and audit log. Todos los par\u00e1metros usados para el filtrado est\u00e1n afectados. Esto afecta a usuarios que abren un enlace dise\u00f1ado o una p\u00e1gina web de terceros"}], "lastModified": "2022-02-10T17:05:37.650", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:nagios:log_server:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D0080172-D0FB-4488-A74D-58DAC7DCFB20", "versionEndExcluding": "2.1.9"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}