Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-24m7-qjg5-vgqc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Bulk Modifications functionality in Nagios XI versions prior to 5.8.5 is vulnerable to SQL injection. Exploitation requires the malicious actor to be authenticated to the vulnerable system, but once authenticated they would be able to execute arbitrary sql queries.

The Bulk Modifications functionality in Nagios XI versions prior to 5.8.5 is vulnerable to SQL injection. Exploitation requires the malicious actor to be authenticated to the vulnerable system, but once authenticated they would be able to execute arbitrary sql queries.

EPSS

Процентиль: 96%
0.30647
Средний

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
nvd
почти 4 года назад

The Bulk Modifications functionality in Nagios XI versions prior to 5.8.5 is vulnerable to SQL injection. Exploitation requires the malicious actor to be authenticated to the vulnerable system, but once authenticated they would be able to execute arbitrary sql queries.

EPSS

Процентиль: 96%
0.30647
Средний

Дефекты

CWE-89