CVE-2023-40931
Summary
| CVE | CVE-2023-40931 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-19 23:15:00 UTC |
| Updated | 2023-09-22 01:11:00 UTC |
| Description | A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Disclosures - Nagios | MISC | www.nagios.com | |
| Nagios XI vulnerabilities resulting in privilege escalation (& more) - Outpost24 | MISC | outpost24.com | |
| Nagios - Network, Server and Log Monitoring Software | MISC | nagios.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 378884 Nagios XI Multiple Vulnerabilities