github.com
https://github.com/NagVis/nagvis/commit/71aba7f46f79d846e1df037f165d206a2cd1d22a CVE-2022-46945
CRITICAL
NagVis 1.9.33 - Arbitrary File Read
Record summary
CVE-2022-46945 has a selected CVSS score of 9.1 (critical); EIP currently links 1 catalogued exploit.
Description
Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagVisHoverUrl.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 15, 2025 · Source: CVE List
Proofs of concept
1Catalogued exploits
ExploitDBNagVis 1.9.33 - Arbitrary File ReadExploitDB exploitby xerosecNot analyzed1 file
References
5github.com
https://github.com/NagVis/nagvis/compare/nagvis-1.9.33...nagvis-1.9.34 lists.debian.org
https://lists.debian.org/debian-lts-announce/2025/05/msg00000.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-46945 sonarsource.com
https://www.sonarsource.com/blog/checkmk-rce-chain-3