ArangoDB Community Edition 3.4.2-1 contains multiple cross-site scripting vulnerabilities in the Aardvark web admin interface (index.html) through search, user management, and API parameters. Attackers can inject scripts via parameters in /_db/_system/_admin/aardvark/index.html to execute JavaScript in authenticated users' browsers.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 15 Feb 2026 14:15:00 +0000

Type Values Removed Values Added
Description ArangoDB Community Edition 3.4.2-1 contains multiple cross-site scripting vulnerabilities in the Aardvark web admin interface (index.html) through search, user management, and API parameters. Attackers can inject scripts via parameters in /_db/_system/_admin/aardvark/index.html to execute JavaScript in authenticated users' browsers.
Title ArangoDB Community Edition 3.4.2-1 XSS via aardvark admin interface
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-02-15T13:58:50.426Z

Reserved: 2026-02-15T13:04:29.728Z

Link: CVE-2019-25367

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-15T14:16:05.083

Modified: 2026-02-15T14:16:05.083

Link: CVE-2019-25367

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses