QID 375516
Date Published: 2021-05-04
QID 375516: Nagios XI 5.7.5 Have Multiple Vulnerabilities
Nagios Core is a free and open source computer-software application that monitors systems, networks and infrastructure. Nagios offers monitoring and alerting services for servers, switches, applications and services.
CVE-2021-25297-An OS command injection as the apache user through variables passed into the Config Wizard.
CVE-2021-25298-An OS command injection as the apache user through variables passed into the Config Wizard.
CVE-2021-25299-XSS vulnerability in the SSH Terminal page.
Affected version:
Version: 5.7.5
QID Detection Logic:(Authenticated)
It will check for vulnerable version of Nagios Core from version file.
Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary OS and files command which may lead to remote code execution.
- Nagios XI -
www.nagios.com/downloads/nagios-xi/change-log/
CVEs related to QID 375516
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Nagios XI |
|