CVE-2021-28925: SQL Injection
Published Apr 8, 2021
·Updated
SQL injection vulnerability in Nagios Network Analyzer before 2.4.3 via the o[col] parameter to api/checks/read/.
Affected Software
1 affected component
Nagios Network Analyzer<2.4.3
Event History
Apr 8, 2021
CVE Published
via MITRE·12:57 PM
Data Sourced
via MITRE·12:57 PM
Description
Frequently Asked Questions
1
What is CVE-2021-28925?
CVE-2021-28925 is a SQL injection vulnerability in Nagios Network Analyzer before version 2.4.3.
2
How severe is CVE-2021-28925?
CVE-2021-28925 has a severity rating of 9.8 (Critical).
3
How does CVE-2021-28925 affect Nagios Network Analyzer?
CVE-2021-28925 affects Nagios Network Analyzer versions prior to 2.4.3 and can be exploited through the o[col] parameter in api/checks/read/.
4
How can I fix CVE-2021-28925?
To fix CVE-2021-28925, you should update Nagios Network Analyzer to version 2.4.3 or later.
5
What is CWE-89?
CWE-89 refers to SQL injection vulnerabilities, which can allow an attacker to execute arbitrary SQL commands on a target system.