No analysis available yet.
Vendor Solution
Nagios addresses this vulnerability as "Fixed XSS in fusionwindow parameter."
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 06 Nov 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nagios:fusion:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Fri, 31 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Oct 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nagios
Nagios fusion |
|
| Vendors & Products |
Nagios
Nagios fusion |
Thu, 30 Oct 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nagios Fusion versions prior to 4.1.5 are vulnerable to cross-site scripting (XSS) via the "fusionwindow" parameter. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser. | |
| Title | Nagios Fusion < 4.1.5 XSS via fusionwindow Parameter | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-17T21:36:22.437Z
Reserved: 2025-10-28T17:14:53.788Z
Link: CVE-2018-25119
Updated: 2025-10-31T15:23:00.090Z
Status : Analyzed
Published: 2025-10-30T22:15:37.550
Modified: 2025-11-06T18:22:07.517
Link: CVE-2018-25119
No data.
OpenCVE Enrichment
Updated: 2025-10-31T10:14:00Z