ZeroHour

CVE-2019-9165

PoC
CVSS 3.1
9.8 critical
EPSS
5%p92
Published
()
Modified
Description

SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicious user id.

Vendors
nagios
Products
nagios xi
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.