First published: Thu Apr 08 2021(Updated: )
SQL injection vulnerability in Nagios Network Analyzer before 2.4.3 via the o[col] parameter to api/checks/read/.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Network Analyzer | <2.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28925 is a SQL injection vulnerability in Nagios Network Analyzer before version 2.4.3.
CVE-2021-28925 has a severity rating of 9.8 (Critical).
CVE-2021-28925 affects Nagios Network Analyzer versions prior to 2.4.3 and can be exploited through the o[col] parameter in api/checks/read/.
To fix CVE-2021-28925, you should update Nagios Network Analyzer to version 2.4.3 or later.
CWE-89 refers to SQL injection vulnerabilities, which can allow an attacker to execute arbitrary SQL commands on a target system.