ArangoDB Community Edition 3.4.2-1 contains multiple cross-site scripting vulnerabilities in the Aardvark web admin interface (index.html) through search, user management, and API parameters. Attackers can inject scripts via parameters in /_db/_system/_admin/aardvark/index.html to execute JavaScript in authenticated users' browsers.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 16 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arangodb
Arangodb arangodb Community Edition |
|
| Vendors & Products |
Arangodb
Arangodb arangodb Community Edition |
Sun, 15 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ArangoDB Community Edition 3.4.2-1 contains multiple cross-site scripting vulnerabilities in the Aardvark web admin interface (index.html) through search, user management, and API parameters. Attackers can inject scripts via parameters in /_db/_system/_admin/aardvark/index.html to execute JavaScript in authenticated users' browsers. | |
| Title | ArangoDB Community Edition 3.4.2-1 XSS via aardvark admin interface | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-15T13:58:50.426Z
Reserved: 2026-02-15T13:04:29.728Z
Link: CVE-2019-25367
No data.
Status : Received
Published: 2026-02-15T14:16:05.083
Modified: 2026-02-15T14:16:05.083
Link: CVE-2019-25367
No data.
OpenCVE Enrichment
Updated: 2026-02-16T09:43:02Z
Weaknesses