CVE-2020-6586: Nagios

Medium severity, CVSS 5.4. EPSS: 19% chance of exploitation in the next 30 days.

Nagios Log Server 2.1.3 allows XSS by visiting /profile and entering a crafted name field that is mishandled on the /admin/users page. Any malicious user with limited access can store an XSS payload in his Name. When any admin views this, the XSS is triggered.

Affected products

  • Nagios Nagios: version 2.1.3 only

Published 2020-03-16. Last modified 2026-06-17.