Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2023-40931
HistorySep 19, 2023 - 12:00 a.m.

CVE-2023-40931

2023-09-1900:00:00
mitre
github.com
sql injection
nagios xi
authenticated attackers
arbitrary commands
post request

AI Score

8.3

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php

AI Score

8.3

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2023-40931