Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source Groups page (percentile calculator menu). An attacker can supply a malicious payload which is stored by the application and later rendered in the context of other users. When a victim views the affected page the injected script executes in the victim's browser context.
Advisories

No advisories yet.

Fixes

Solution

Nagios addresses this vulnerability as "An XSS vulnerability has been discovered in the Source Groups page" and "Fixed an XSS vulnerability in percentile calculator menu."


Workaround

No workaround given by the vendor.

History

Mon, 17 Nov 2025 21:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:nagios:network_analyzer:2024:*:*:*:*:*:*:*

Thu, 06 Nov 2025 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:nagios:network_analyzer:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Fri, 31 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Oct 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Nagios
Nagios network Analyzer
Vendors & Products Nagios
Nagios network Analyzer

Thu, 30 Oct 2025 21:30:00 +0000

Type Values Removed Values Added
Description Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source Groups page (percentile calculator menu). An attacker can supply a malicious payload which is stored by the application and later rendered in the context of other users. When a victim views the affected page the injected script executes in the victim's browser context.
Title Nagios Network Analyzer < 2024R1 Source Groups / Percentile Calculator Menu Stored XSS
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-11-17T21:36:25.596Z

Reserved: 2025-04-15T19:15:22.581Z

Link: CVE-2025-34278

cve-icon Vulnrichment

Updated: 2025-10-31T15:10:07.207Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-30T22:15:48.360

Modified: 2025-11-06T18:15:26.803

Link: CVE-2025-34278

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-31T10:13:30Z