Medium severity5.4NVD Advisory· Published Oct 30, 2025· Updated Jun 17, 2026
CVE-2020-36858
CVE-2020-36858
Description
Nagios Log Server versions prior to 2.1.6 contain cross-site scripting (XSS) vulnerabilities via the web interface on the Create User, Edit User, and Manage Host Lists pages. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<2.1.6+ 2 more
- (no CPE)range: <2.1.6
- (no CPE)range: 0
- cpe:2.3:a:nagios:log_server:*:*:*:*:*:*:*:*range: <2.1.6
Patches
Vulnerability mechanics
References
2- www.vulncheck.com/advisories/nagios-log-server-xss-via-create-user-edit-user-and-manage-host-lists-pagesnvdThird Party Advisory
- www.nagios.com/changelog/nagios-log-server-2024r1/nvdRelease Notes
News mentions
0No linked articles in our index yet.