Lucene search

K
cvelistMitreCVELIST:CVE-2023-40931
HistorySep 19, 2023 - 12:00 a.m.

CVE-2023-40931

2023-09-1900:00:00
mitre
www.cve.org
4
cve-2023-40931
nagios xi
sql injection
authenticated attackers
arbitrary sql commands

AI Score

7.8

Confidence

High

EPSS

0.002

Percentile

58.9%

A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php

AI Score

7.8

Confidence

High

EPSS

0.002

Percentile

58.9%

Related for CVELIST:CVE-2023-40931