CVE-2018-10736: SQL Injection
Published May 16, 2018
·Updated
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.
Affected Software
2 affected components
Nagios Nagios XI>=5.2.0<=5.2.9
Nagios Nagios XI>=5.4.0<5.4.13
Event History
May 16, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-10736?
CVE-2018-10736 is rated as a critical vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2018-10736?
To fix CVE-2018-10736, update Nagios XI to version 5.4.13 or later.
3
What software is affected by CVE-2018-10736?
CVE-2018-10736 affects Nagios XI versions between 5.2.0 and 5.4.12.
4
What type of vulnerability is CVE-2018-10736?
CVE-2018-10736 is a SQL injection vulnerability affecting the admin/info.php key1 parameter.
5
Can CVE-2018-10736 allow unauthorized access?
Yes, CVE-2018-10736 can be exploited to gain unauthorized access to sensitive data in the database.