Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r46p-cr3r-8h8f

Опубликовано: 05 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6

Описание

Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in visApi.php. An authenticated user can inject system commands via unsanitized parameters such as host, resulting in remote code execution.

Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in visApi.php. An authenticated user can inject system commands via unsanitized parameters such as host, resulting in remote code execution.

EPSS

Процентиль: 98%
0.46601
Средний

8.6 High

CVSS4

Дефекты

CWE-78

Связанные уязвимости

nvd
6 месяцев назад

Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in `visApi.php`. An authenticated user can inject system commands via unsanitized parameters such as `host`, resulting in remote code execution.

EPSS

Процентиль: 98%
0.46601
Средний

8.6 High

CVSS4

Дефекты

CWE-78