CVE-2023-40933
nagios xi
A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function.
- CVSS
- 8.8
- EPSS
- 3.11% 86.5% percentile
- CISA KEV
- Not listed
- Published
- 2023.09.20