Lucene search

K
cvelistMitreCVELIST:CVE-2021-40344
HistoryOct 26, 2021 - 10:52 a.m.

CVE-2021-40344

2021-10-2610:52:00
mitre
www.cve.org
4
nagios xi
custom includes
remote command execution
cve-2021-40344
admin panel
upload files
arbitrary extensions
mime type
crafted php script

AI Score

7.5

Confidence

High

EPSS

0.142

Percentile

95.7%

An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can upload files with arbitrary extensions as long as the MIME type corresponds to an image. Therefore it is possible to upload a crafted PHP script to achieve remote command execution.

AI Score

7.5

Confidence

High

EPSS

0.142

Percentile

95.7%

Related for CVELIST:CVE-2021-40344