- EPSS 77.1%
- Published 15.02.2021 13:15:12
- Last modified 14.03.2025 17:07:47
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled input by a si...
CVE-2021-25299
- EPSS 79.93%
- Published 15.02.2021 13:15:12
- Last modified 21.11.2024 05:54:42
Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an...
CVE-2021-3193
- EPSS 22.6%
- Published 26.01.2021 18:16:28
- Last modified 21.11.2024 06:21:06
Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated attacker to execute remote code as the apache user.
- EPSS 90.44%
- Published 13.01.2021 21:15:12
- Last modified 21.11.2024 05:27:37
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature is mishandled during a plugin upload, a remote, authenticated admin user can execute operating-system commands.
CVE-2020-27990
- EPSS 17.74%
- Published 16.11.2020 17:15:13
- Last modified 21.11.2024 05:22:09
Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent).
CVE-2020-27991
- EPSS 17.74%
- Published 16.11.2020 17:15:13
- Last modified 21.11.2024 05:22:09
Nagios XI before 5.7.5 is vulnerable to XSS in Account Information (Email field).
CVE-2020-27988
- EPSS 56.62%
- Published 16.11.2020 17:15:12
- Last modified 21.11.2024 05:22:09
Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).
CVE-2020-27989
- EPSS 17.74%
- Published 16.11.2020 17:15:12
- Last modified 21.11.2024 05:22:09
Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard).
- EPSS 13.91%
- Published 16.11.2020 03:15:12
- Last modified 21.11.2024 05:23:06
Improper input validation in the Auto-Discovery component of Nagios XI before 5.7.5 allows an authenticated attacker to execute remote code.
CVE-2020-5796
- EPSS 0.11%
- Published 13.11.2020 20:15:17
- Last modified 21.11.2024 05:34:36
Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the permissions of files, resulting in low-privileged users being able to write to and execute arbitrary PHP code with root privilege...