Nagios Network Analyzer Stored Cross-Site Scripting Vulnerability
Vulnerability
A stored cross-site scripting vulnerability has been identified in Nagios Network Analyzer versions prior to 2024R1. This issue resides in the Source Groups page, specifically within the percentile calculator menu. The vulnerability allows an attacker to inject a malicious payload that is saved by the application and later executed in the context of other users' browsers when they view the affected page.
Impact
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the page.
Remediation
Users are advised to upgrade to Nagios Network Analyzer version 2024R1 or above.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
