Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-36857

Опубликовано: 30 окт. 2025
Источник: nvd
CVSS3: 7.2
EPSS Низкий

Описание

Nagios XI versions prior to 5.6.14 contain a post-authentication SQL injection vulnerability in the SNMP Trap Interface page. Exploitation requires an account with administrative privileges to access the affected interface. A user with administrative access could supply crafted input that is not properly sanitized, allowing SQL injection that may lead to unauthorized disclosure or modification of application data or execution of arbitrary SQL commands against the backend database.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*
Версия до 5.6.14 (исключая)

EPSS

Процентиль: 57%
0.00348
Низкий

7.2 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.2
github
3 месяца назад

Nagios XI versions prior to 5.6.14 contain a post-authentication SQL injection vulnerability in the SNMP Trap Interface page. Exploitation requires an account with administrative privileges to access the affected interface. A user with administrative access could supply crafted input that is not properly sanitized, allowing SQL injection that may lead to unauthorized disclosure or modification of application data or execution of arbitrary SQL commands against the backend database.

CVSS3: 6.7
fstec
3 месяца назад

Уязвимость интерфейса SNMP Trap Interface инструмента для мониторинга Nagios XI, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 57%
0.00348
Низкий

7.2 High

CVSS3

Дефекты

CWE-89