First published: Tue Sep 19 2023(Updated: )
A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Nagios XI | <5.11.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-40934.
The severity of CVE-2023-40934 is high with a severity value of 7.2.
The affected software is Nagios XI 5.11.1 and below.
An attacker with privileges to manage host escalations in the Core Configuration Manager can exploit CVE-2023-40934 by executing arbitrary SQL commands through the host escalation notification settings.
Yes, you can find references for CVE-2023-40934 at the following URLs: http://nagios.com, https://outpost24.com/blog/nagios-xi-vulnerabilities/, https://www.nagios.com/products/security/