{"api_version":"1","generated_at":"2026-07-23T11:05:31+00:00","cve":"CVE-2018-8733","urls":{"html":"https://cve.report/CVE-2018-8733","api":"https://cve.report/api/cve/CVE-2018-8733.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-8733","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-8733"},"summary":{"title":"CVE-2018-8733","description":"Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-04-18 00:29:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["CWE-89"],"metrics":[],"references":[{"url":"https://www.exploit-db.com/exploits/44560/","name":"44560","refsource":"EXPLOIT-DB","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root - PHP webapps Exploit","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://blog.redactedsec.net/exploits/2018/04/26/nagios.html","name":"https://blog.redactedsec.net/exploits/2018/04/26/nagios.html","refsource":"MISC","tags":["Exploit","Technical Description","Third Party Advisory"],"title":"CVE-2018-873X - NagiosXI Vulnerability Chaining; Death By a Thousand Cuts | Redacted Security Blog","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.nagios.com/downloads/nagios-xi/change-log/","name":"https://www.nagios.com/downloads/nagios-xi/change-log/","refsource":"MISC","tags":["Release Notes","Vendor Advisory"],"title":"Nagios XI Change Log - Nagios","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://gist.github.com/caleBot/f0a93b5a98574393e0139104eacc2d0f","name":"https://gist.github.com/caleBot/f0a93b5a98574393e0139104eacc2d0f","refsource":"MISC","tags":["Third Party Advisory"],"title":"NagiosXI remote root vulnerability CVE-2018-8733, CVE-2018-8734, CVE-2018-8735, CVE-2018-8736 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/44969/","name":"44969","refsource":"EXPLOIT-DB","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Nagios XI 5.2.6-5.4.12 - Chained Remote Code Execution (Metasploit)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT","name":"https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT","refsource":"MISC","tags":["Release Notes","Vendor Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-8733","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-8733","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"8733","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nagios","cpe5":"nagios_xi","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"8733","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nagios","cpe5":"nagios_xi","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-8733","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://gist.github.com/caleBot/f0a93b5a98574393e0139104eacc2d0f","refsource":"MISC","url":"https://gist.github.com/caleBot/f0a93b5a98574393e0139104eacc2d0f"},{"name":"44560","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/44560/"},{"name":"https://www.nagios.com/downloads/nagios-xi/change-log/","refsource":"MISC","url":"https://www.nagios.com/downloads/nagios-xi/change-log/"},{"name":"https://blog.redactedsec.net/exploits/2018/04/26/nagios.html","refsource":"MISC","url":"https://blog.redactedsec.net/exploits/2018/04/26/nagios.html"},{"name":"https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT","refsource":"MISC","url":"https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT"},{"name":"44969","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/44969/"}]}},"nvd":{"publishedDate":"2018-04-18 00:29:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["CWE-89"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2.0","versionEndExcluding":"5.4.13","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"8733","Ordinal":"125095","Title":"CVE-2018-8733","CVE":"CVE-2018-8733","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"8733","Ordinal":"1","NoteData":"Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"8733","Ordinal":"2","NoteData":"2018-04-17","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"8733","Ordinal":"3","NoteData":"2018-07-04","Type":"Other","Title":"Modified"}]}}}