CVE-2018-25119

Publication date

2025-10-30 21:21:46

Family

VulnCheck

State

PUBLISHED

Description

Nagios Fusion versions prior to 4.1.5 areĀ vulnerable to cross-site scripting (XSS) via theĀ "fusionwindow" parameter. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victims browser.