Medium severity6.4NVD Advisory· Published Apr 2, 2026· Updated Apr 7, 2026
CVE-2026-34803
CVE-2026-34803
Description
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the name parameter to /manage/qos/classes/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- www.vulncheck.com/advisories/endian-firewall-manage-qos-classes-name-stored-cross-site-scriptingnvdThird Party Advisory
- help.endian.com/hc/en-us/sections/360004371358-CommunitynvdRelease Notes
News mentions
0No linked articles in our index yet.