CVE-2023-40934: SQL Injection
A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-40934.
What is the severity of CVE-2023-40934?
The severity of CVE-2023-40934 is high with a severity value of 7.2.
What is the affected software?
The affected software is Nagios XI 5.11.1 and below.
How can an attacker exploit CVE-2023-40934?
An attacker with privileges to manage host escalations in the Core Configuration Manager can exploit CVE-2023-40934 by executing arbitrary SQL commands through the host escalation notification settings.
Are there any references available for CVE-2023-40934?
Yes, you can find references for CVE-2023-40934 at the following URLs: http://nagios.com, https://outpost24.com/blog/nagios-xi-vulnerabilities/, https://www.nagios.com/products/security/