CVE-2021-33179
- EPSS 63.36%
- Veröffentlicht 14.10.2021 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:08:27
The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scripting. An authenticated victim, who accesses a specially crafted malicious URL, would unknowingly execute the attached payload.
CVE-2021-33177
- EPSS 41.84%
- Veröffentlicht 14.10.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:08:27
The Bulk Modifications functionality in Nagios XI versions prior to 5.8.5 is vulnerable to SQL injection. Exploitation requires the malicious actor to be authenticated to the vulnerable system, but once authenticated they would be able to execute arb...
CVE-2021-37223
- EPSS 0.65%
- Veröffentlicht 05.10.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:14:53
Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. Any authenticated user can create scheduled reports containing PDF screenshots of any view in the NagiosXI application. Due to lac...
CVE-2021-36363
- EPSS 1%
- Veröffentlicht 28.09.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:13:36
Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.
CVE-2021-36364
- EPSS 10.9%
- Veröffentlicht 28.09.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:13:36
Nagios XI before 5.8.5 incorrectly allows backup_xi.sh wildcards.
CVE-2021-36365
- EPSS 1%
- Veröffentlicht 28.09.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:13:36
Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.
CVE-2021-36366
- EPSS 10.9%
- Veröffentlicht 28.09.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:13:36
Nagios XI before 5.8.5 incorrectly allows manage_services.sh wildcards.
CVE-2021-38156
- EPSS 84.02%
- Veröffentlicht 15.09.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:16:30
In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.
CVE-2021-37345
- EPSS 0.02%
- Veröffentlicht 13.08.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:14:58
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions.
CVE-2021-37347
- EPSS 0.09%
- Veröffentlicht 13.08.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:14:59
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because getprofile.sh does not validate the directory name it receives as an argument.