First published: Mon Jun 07 2021(Updated: )
Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rename functionality in custom-includes component, which leads to remote code execution by uploading php files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Nagios XI | <=5.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-3277.
The severity of CVE-2021-3277 is high with a severity score of 7.2.
The affected software is Nagios XI version 5.7.5 and earlier.
CVE-2021-3277 allows remote code execution by allowing authenticated admins to upload arbitrary files due to improper validation of the rename functionality in the custom-includes component, which can lead to the execution of uploaded PHP files.
Yes, upgrading Nagios XI to a version beyond 5.7.5 will fix the vulnerability.