Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source Groups page (percentile calculator menu). An attacker can supply a malicious payload which is stored by the application and later rendered in the context of other users. When a victim views the affected page the injected script executes in the victim's browser context.
Advisories

No advisories yet.

Fixes

Solution

Nagios addresses this vulnerability as "An XSS vulnerability has been discovered in the Source Groups page" and "Fixed an XSS vulnerability in percentile calculator menu."


Workaround

No workaround given by the vendor.

History

Thu, 30 Oct 2025 21:30:00 +0000

Type Values Removed Values Added
Description Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source Groups page (percentile calculator menu). An attacker can supply a malicious payload which is stored by the application and later rendered in the context of other users. When a victim views the affected page the injected script executes in the victim's browser context.
Title Nagios Network Analyzer < 2024R1 Source Groups / Percentile Calculator Menu Stored XSS
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-10-30T21:28:11.933Z

Reserved: 2025-04-15T19:15:22.581Z

Link: CVE-2025-34278

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-30T22:15:48.360

Modified: 2025-10-30T22:15:48.360

Link: CVE-2025-34278

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.