Metrics
Affected Vendors & Products
No advisories yet.
Solution
Nagios addresses this vulnerability as "Fixed potential SQL injection vulnerability in legacy CCM for authenticated users."
Workaround
No workaround given by the vendor.
Mon, 24 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Mon, 17 Nov 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nagios:nagios_xi:2012:*:*:*:*:*:*:* |
Thu, 06 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nagios nagios Xi
|
|
| CPEs | cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:* cpe:2.3:a:nagios:nagios_xi:2012:r1.0:*:*:*:*:*:* cpe:2.3:a:nagios:nagios_xi:2012:r1.1:*:*:*:*:*:* cpe:2.3:a:nagios:nagios_xi:2012:r1.2:*:*:*:*:*:* |
|
| Vendors & Products |
Nagios nagios Xi
|
|
| Metrics |
cvssV3_1
|
Fri, 31 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Oct 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nagios
Nagios xi |
|
| Vendors & Products |
Nagios
Nagios xi |
Thu, 30 Oct 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nagios XI versions prior to 2012R1.3 contain a SQL injection vulnerability in the legacy Core Configuration Manager (CCM) interface. Authenticated users could manipulate SQL queries by supplying crafted input to specific CCM parameters, potentially allowing access to configuration data stored in the application database. Successful exploitation could disclose or modify notification data and, in some cases, impact the application database more broadly. | |
| Title | Nagios XI < 2012R1.3 Authenticated SQL Injection in Legacy CCM | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-11-24T20:28:50.030Z
Reserved: 2025-10-28T20:51:25.373Z
Link: CVE-2012-10063
Updated: 2025-10-31T17:43:36.338Z
Status : Analyzed
Published: 2025-10-30T22:15:35.913
Modified: 2025-11-06T15:09:58.743
Link: CVE-2012-10063
No data.
OpenCVE Enrichment
Updated: 2025-10-31T10:13:29Z