CVE-2019-9165

CRITICAL

Nagios XI < 5.5.11 - SQL Injection via Fusekeys API

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicious user id.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
https://www.nagios.com/products/security/
Product, Vendor Advisory x_refsource_confirm
https://www.nagios.com/downloads/nagios-xi/change-log/

Scores

CVSS v3 9.8
EPSS 0.0629
EPSS Percentile 91.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
nagios/nagios_xi < 5.5.11
Published Mar 28, 2019
Tracked Since Feb 18, 2026