First published: Sat Jul 15 2023(Updated: )
PNP4Nagios through 81ebfc5 lacks CSRF protection in the AJAX controller. This affects 0.6.26.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PNP4Nagios | =0.6.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38349 is considered a moderate severity vulnerability due to the lack of CSRF protection in the AJAX controller.
To fix CVE-2023-38349, update PNP4Nagios to version 0.6.27 or later where the CSRF protection issue is addressed.
CVE-2023-38349 affects PNP4Nagios version 0.6.26.
CVE-2023-38349 is a Cross-Site Request Forgery (CSRF) vulnerability.
Users of PNP4Nagios version 0.6.26 are impacted by CVE-2023-38349 due to insufficient CSRF protection.