CVE-2024-54960: SQL Injection
Published Feb 20, 2025
·Updated
A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab component.
Affected Software
2 affected components
Nagios XI
Nagios Nagios XI=2024-r1.2.2
Event History
Feb 20, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-54960?
CVE-2024-54960 is rated as a high severity SQL Injection vulnerability.
2
How do I fix CVE-2024-54960?
To fix CVE-2024-54960, update your Nagios XI installation to the latest version where this vulnerability is patched.
3
What kind of attack can be executed using CVE-2024-54960?
An attacker can exploit CVE-2024-54960 to execute arbitrary SQL commands through crafted input in the History Tab.
4
Which software is affected by CVE-2024-54960?
CVE-2024-54960 affects Nagios XI version 2024R1.2.2.
5
Is authentication required to exploit CVE-2024-54960?
No, CVE-2024-54960 can be exploited by an unauthenticated remote attacker.