CVE-2020-28905: Code Injection
Published May 24, 2021
·Updated
Improper Input Validation in Nagios Fusion 4.1.8 and earlier allows an authenticated attacker to execute remote code via table pagination.
Affected Software
1 affected component
Nagios Fusion<=4.1.8
Event History
May 24, 2021
CVE Published
via MITRE·12:43 PM
Data Sourced
via MITRE·12:43 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-28905.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Improper Input Validation in Nagios Fusion 4.1.8 and earlier allows an authenticated attacker to execute remote code via table pagination.'
3
What is the severity of CVE-2020-28905?
The severity of CVE-2020-28905 is high with a severity value of 8.8.
4
What is the affected software of CVE-2020-28905?
The affected software is Nagios Fusion 4.1.8 and earlier.
5
How can an authenticated attacker exploit this vulnerability?
An authenticated attacker can exploit this vulnerability by executing remote code via table pagination.