CVE-2025-29471 Details
Description
Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email field.
A stored cross-site scripting vulnerability has been identified in Nagios Log Server version 2024R1.3.1. This vulnerability allows a low-privileged user to inject malicious JavaScript into the 'email' field of their profile. When an administrator reviews the audit logs, the injected script executes, potentially leading to unauthorized creation of admin accounts. In certain configurations, this vulnerability could be chained to achieve remote code execution.
Users can update to Nagios Log Server version 2024R1.3.2 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.exploit-db.com/exploits/52117 | [email protected] | ExploitThird Party Advisory |
| https://www.nagios.com/changelog/#log-server | [email protected] | Release Notes |
| https://youtu.be/MvJuIkdTSQg | [email protected] | Exploit |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| nagios log server | 2024 r1.3.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2025 | Initial Analysis | [email protected] |
| Apr 16, 2025 | CVE Modified | CISA-ADP |
| Apr 15, 2025 | New CVE Received | [email protected] |