CVE-2024-58272

Nagios Log Server versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability where an attacker-supplied username containing JavaScript is stored and later rendered without proper encoding/escaping in admin or user-facing pages. When an authenticated victim loads the affected page, the browser executes the injected script in the victim's context.
CVSS

No CVSS.

Configurations

No configuration.

History

30 Oct 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-30 22:15

Updated : 2025-10-30 22:15


NVD link : CVE-2024-58272

Mitre link : CVE-2024-58272

CVE.ORG link : CVE-2024-58272


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')