Back

HIGH

Nagios XI < 2012R1.3 Authenticated SQL Injection in Legacy CCM

Published Oct 30, 2025

Description

Nagios XI versions prior to 2012R1.3 contain a SQL injection vulnerability in the legacy Core Configuration Manager (CCM) interface. Authenticated users could manipulate SQL queries by supplying crafted input to specific CCM parameters, potentially allowing access to configuration data stored in the application database. Successful exploitation could disclose or modify notification data and, in some cases, impact the application database more broadly.

Affected products

Remediation

Vendor solution

Nagios addresses this vulnerability as "Fixed potential SQL injection vulnerability in legacy CCM for authenticated users."

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Oct 30, 2025
Updated Nov 24, 2025
Reserved Oct 28, 2025
CISA Vulnrichment
Updated Nov 24, 2025
NVD
Status Analyzed
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a