CVE-2023-40934
Summary
| CVE | CVE-2023-40934 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-19 23:15:00 UTC |
| Updated | 2023-09-22 01:20:00 UTC |
| Description | A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Disclosures - Nagios | MISC | www.nagios.com | |
| Nagios XI vulnerabilities resulting in privilege escalation (& more) - Outpost24 | MISC | outpost24.com | |
| Nagios - Network, Server and Log Monitoring Software | MISC | nagios.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 378884 Nagios XI Multiple Vulnerabilities