A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 25 Sep 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-25T14:26:23.515Z
Reserved: 2023-08-22T00:00:00
Link: CVE-2023-40931
Updated: 2024-08-02T18:46:11.351Z
Status : Modified
Published: 2023-09-19T23:15:09.153
Modified: 2024-11-21T08:20:19.003
Link: CVE-2023-40931
No data.
OpenCVE Enrichment
No data.
Weaknesses