Nagios XI < 5.7.4 Core Config Manager (CCM) SQL Injection via Object Edit Pages
Published Oct 30, 2025
8.7
HIGHCVSS 4.0
EPSS 0.91%
Description
The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.7 / Nagios XI 5.7.4 contains multiple SQL injection vulnerabilities in the object edit pages. Unsanitized user-supplied input was incorporated into SQL queries used by configuration object editors, allowing authenticated users to inject SQL fragments. Successful exploitation could lead to unauthorized disclosure or modification of configuration and application data, and in some environments could allow further compromise of the application or backend database.
Affected products
-
- Version 0StatusaffectedConstraints<5.7.4
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Nagios addresses this vulnerability as "Fixed various SQL injection security vulnerabilities in the object edit pages."
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-30814 Advisory
- https://www.nagios.com/changelog/nagios-xi/ release-notespatchRelease Notes
- https://www.vulncheck.com/advisories/nagios-xi-ccm-sqli-via-object-edit-pages third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-30814 | Advisory | |
| https://www.nagios.com/changelog/nagios-xi/ | release-notespatchRelease Notes | |
| https://www.vulncheck.com/advisories/nagios-xi-ccm-sqli-via-object-edit-pages | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.