Back

HIGH

A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings

Published Sep 19, 2023

Description

A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Sep 19, 2023
Updated Jul 9, 2026
Reserved Aug 22, 2023

CISA Vulnrichment

Updated Sep 24, 2024

NVD

Status Modified
Modified Jul 9, 2026

Red Hat

No data

ENISA EUVD

Assigner mitre
Published Sep 19, 2023
Updated Jul 9, 2026

GitHub

No data