CVE-2023-40931
MEDIUM NUCLEINagios XI <5.11.1 - SQL Injection
Title source: llmDescription
A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php
Exploits (3)
nomisec
WORKING POC
1 stars
by sealldeveloper · poc
https://github.com/sealldeveloper/CVE-2023-40931-PoC
nomisec
WORKING POC
by datboi6942 · poc
https://github.com/datboi6942/Nagios-XI-s-CVE-2023-40931-Exploit
Nuclei Templates (1)
Nagios XI v5.11.0 - SQL Injection
MEDIUMVERIFIEDby ritikchaddha
Shodan:
title:"Nagios XI"
FOFA:
app="nagios-xi"
Scores
CVSS v3
6.5
EPSS
0.8621
EPSS Percentile
99.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-89
Status
published
Products (1)
nagios/nagios_xi
5.11.0 - 5.11.2
Published
Sep 19, 2023
Tracked Since
Feb 18, 2026