Record summary

CVE-2023-40931 has a selected CVSS score of 6.5 (medium); EIP currently links 3 repository PoCs and 1 Nuclei template.

Description

A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php

Description source: CVE List

Exploitation context

Available material

Repository PoCs
3
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 25, 2024 · Source: CVE List

Proofs of concept

3

Repository PoCs

GitHubsealldeveloper/CVE-2023-40931-PoCRepository PoCby sealldeveloperStars: 1Not analyzed1 file

508 B

GitHub

PoC details
GitHubdatboi6942/Nagios-XI-s-CVE-2023-40931-ExploitRepository PoCby datboi6942Stars: 0Not analyzed1 file

4.0 KiB

GitHub

PoC details
GitHubG4sp4rCS/CVE-2023-40931-POCRepository PoCby G4sp4rCSStars: 0Not analyzed4 files

9.0 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMNagios XI v5.11.0 - SQL InjectionCVSS 6.5

A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php.

Impact

Successful exploitation of this vulnerability allows an authenticated attackers to execute arbitrary SQL commands.

Remediation

Upgrade Nagios XI to a patched version or apply the vendor-supplied patch to mitigate this vulnerability.

WeaknessesCWE-89
Authorsritikchaddha
Template tagscve2023cveauthenticatednagiosxisqlinagiosvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*
Shodan: title:"Nagios XI"
FOFA: app="nagios-xi"
Google: intitle:"nagios xi"

Source: ProjectDiscovery

References

4