CVE-2024-24401: SQL Injection
Published Feb 26, 2024
·Updated
SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.
Affected Software
2 affected components
Nagios XI
Nagios Nagios XI=2024-r1.0.1
Event History
Feb 26, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24401?
CVE-2024-24401 has been classified as a high-severity SQL Injection vulnerability.
2
How do I fix CVE-2024-24401?
To fix CVE-2024-24401, update Nagios XI to the latest version from the official vendor.
3
What types of attacks can exploit CVE-2024-24401?
CVE-2024-24401 allows remote attackers to execute arbitrary code through crafted SQL injection payloads.
4
In which component is CVE-2024-24401 found?
CVE-2024-24401 is present in the monitoringwizard.php component of Nagios XI.
5
Who is affected by CVE-2024-24401?
Users of Nagios XI version 2024R1.01 are affected by CVE-2024-24401.