First published: Mon Apr 30 2018(Updated: )
An issue was discovered in Nagios XI 5.4.13. A registered user is able to use directory traversal to read local files, as demonstrated by URIs beginning with index.php?xiwindow=./ and config/?xiwindow=../ substrings.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios | =5.4.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10553 has a medium severity level due to its potential for unauthorized file access.
To fix CVE-2018-10553, upgrade Nagios XI to the latest version where the vulnerability is patched.
Anyone using Nagios XI version 5.4.13 is vulnerable to CVE-2018-10553.
CVE-2018-10553 allows a directory traversal attack, enabling users to read sensitive files on the server.
A temporary workaround for CVE-2018-10553 might include restricting user permissions to limit access to sensitive files.