CVE 5.8 MEDIUM

Client-side path traversal in Guardian/CMC before 25.2.0_CVE-2025-3718

5.8 / 10
MEDIUM
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:L/VI:H/VA:H/SC:L/SI:L/SA:L

Description

A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter. An authenticated user with limited privileges can craft a malicious URL which, if visited by an authenticated victim, leads to a Cross-Site Scripting (XSS) attack.

Basic Information

ID CVE-2025-3718
Source Nozomi
Published Oct 7, 2025 at 12:33
Modified Oct 7, 2025 at 13:21

Affected Product

Vendor Nozomi Networks
Product Guardian
Affected Versions Nozomi Networks Guardian 0
Nozomi Networks CMC 0

CWE Classification

References

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.