A SQL injection vulnerability in Nagios XI v5.11.1 and...
High severity
Unreviewed
Published
Sep 20, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Sep 19, 2023
Published to the GitHub Advisory Database
Sep 20, 2023
Last updated
Apr 4, 2024
A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function.
References