Metrics
Affected Vendors & Products
No advisories yet.
Solution
Nagios addresses this vulnerability as "Fixed SQL injection vulnerability in the edit page for SNMP Trap Interface."
Workaround
No workaround given by the vendor.
Fri, 31 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Fri, 31 Oct 2025 10:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Nagios Nagios xi | |
| Vendors & Products | Nagios Nagios xi | 
Thu, 30 Oct 2025 22:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Nagios XI versions prior to 5.7.5 contain a SQL injection vulnerability in the SNMP Trap Interface edit page. Exploitation requires an account with administrative privileges to access the affected interface. A user with administrative access could supply crafted input that is not properly sanitized, allowing SQL injection that may lead to unauthorized disclosure or modification of application data or execution of arbitrary SQL commands against the backend database. | |
| Title | Nagios XI < 5.7.5 SQL injection via SNMP Trap Interface Edit Page | |
| Weaknesses | CWE-89 | |
| References |  | |
| Metrics | cvssV4_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-10-31T13:23:30.086Z
Reserved: 2025-10-30T14:33:17.565Z
Link: CVE-2020-36869
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-10-31T13:05:36.225Z
 NVD
                        NVD
                    Status : Received
Published: 2025-10-30T22:15:39.967
Modified: 2025-10-30T22:15:39.967
Link: CVE-2020-36869
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    Updated: 2025-10-31T10:12:56Z