Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source Groups page (percentile calculator menu). An attacker can supply a malicious payload which is stored by the application and later rendered in the context of other users. When a victim views the affected page the injected script executes in the victim's browser context.
References
| Link | Resource |
|---|---|
| https://www.nagios.com/changelog/#network-analyzer | Release Notes |
| https://www.nagios.com/products/security/#network-analyzer | Product |
| https://www.vulncheck.com/advisories/nagios-network-analyzer-source-groups-percentile-calculator-menu-stored-xss | Third Party Advisory |
Configurations
History
06 Nov 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-30 22:15
Updated : 2025-11-06 18:15
NVD link : CVE-2025-34278
Mitre link : CVE-2025-34278
CVE.ORG link : CVE-2025-34278
JSON object : View
Products Affected
nagios
- network_analyzer
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
