Nagios Network Analyzer Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in Nagios Network Analyzer versions prior to 2024R1. This issue resides in the Source Groups page, specifically within the percentile calculator menu. The vulnerability allows an attacker to inject a malicious payload that is saved by the application and later executed in the context of other users' browsers when they view the affected page.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the page.

Remediation

Users are advised to upgrade to Nagios Network Analyzer version 2024R1 or above.

Added: Oct 30, 2025, 10:26 PM
Updated: Oct 30, 2025, 10:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.0
exploitability
5.0
remediation
7.7
relevance
0.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.