CVE-2025-67255: SQL Injection
Published Dec 29, 2025
·Updated
In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to exploit a SQL Injection vulnerability.
Affected Software
2 affected components
Nagios Nagios XI
Nagios Nagios XI=2026-r1.0.1
Event History
Dec 29, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-67255?
CVE-2025-67255 is classified as a high-severity vulnerability due to its potential for SQL Injection exploitation.
2
How do I fix CVE-2025-67255?
To fix CVE-2025-67255, you should ensure that all dashboard parameters in Nagios XI are properly filtered and validated.
3
What types of systems are affected by CVE-2025-67255?
CVE-2025-67255 affects all versions of Nagios XI, specifically the 2026R1.0.1 build 1762361101.
4
Who can exploit CVE-2025-67255?
Any authenticated user can exploit CVE-2025-67255 due to the lack of proper filtering of dashboard parameters.
5
What is the potential impact of exploiting CVE-2025-67255?
Exploiting CVE-2025-67255 can lead to unauthorized database access and manipulation through SQL Injection.