Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source Groups page (percentile calculator menu). An attacker can supply a malicious payload which is stored by the application and later rendered in the context of other users. When a victim views the affected page the injected script executes in the victim's browser context.
                
            Metrics
Affected Vendors & Products
Advisories
    No advisories yet.
Fixes
    Solution
Nagios addresses this vulnerability as "An XSS vulnerability has been discovered in the Source Groups page" and "Fixed an XSS vulnerability in percentile calculator menu."
Workaround
No workaround given by the vendor.
References
        History
                    Thu, 30 Oct 2025 21:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source Groups page (percentile calculator menu). An attacker can supply a malicious payload which is stored by the application and later rendered in the context of other users. When a victim views the affected page the injected script executes in the victim's browser context. | |
| Title | Nagios Network Analyzer < 2024R1 Source Groups / Percentile Calculator Menu Stored XSS | |
| Weaknesses | CWE-79 | |
| References |  | |
| Metrics | cvssV4_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-10-30T21:28:11.933Z
Reserved: 2025-04-15T19:15:22.581Z
Link: CVE-2025-34278
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Received
Published: 2025-10-30T22:15:48.360
Modified: 2025-10-30T22:15:48.360
Link: CVE-2025-34278
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    No data.