ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-3325
Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option).

Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option). This issue occurred because a new access-control feature was introduced without considering that some exiting installations became unsafe, upon an update to 3.13.0, unless the new feature was immediately configured.

NVD description · AI analysis pending
9.82% PoC
  • fibranet monitorix
  • fibranet fedora
CVE-2018-7649
Monitorix before 3.10.1 allows XSS via CGI variables.

Monitorix before 3.10.1 allows XSS via CGI variables.

NVD description · AI analysis pending
6.1<1%
  • fibranet monitorix