Lucene search

K
prionPRIOn knowledge basePRION:CVE-2018-16146
HistorySep 05, 2018 - 9:29 p.m.

Command injection

2018-09-0521:29:00
PRIOn knowledge base
www.prio-n.com
7

7.8 High

AI Score

Confidence

High

0.03 Low

EPSS

Percentile

90.9%

The web management console of Opsview Monitor 5.4.x before 5.4.2 provides functionality accessible by an authenticated administrator to test notifications that are triggered under certain configurable events. The value parameter is not properly sanitized, leading to arbitrary command injection with the privileges of the nagios user account.

CPENameOperatorVersion
opsviewge5.4.0
opsviewlt5.4.2

7.8 High

AI Score

Confidence

High

0.03 Low

EPSS

Percentile

90.9%