First published: Mon May 24 2021(Updated: )
Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via installation of a malicious component containing PHP code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Fusion | <=4.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-28904.
The severity of CVE-2020-28904 is critical with a severity value of 9.8.
The affected software is Nagios Fusion 4.1.8 and earlier.
CVE-2020-28904 allows for privilege escalation by executing with unnecessary privileges as nagios via installation of a malicious component containing PHP code.
To fix CVE-2020-28904, it is recommended to update to a version later than 4.1.8 of Nagios Fusion.