CVE-2023-40931

MEDIUM NUCLEI

Nagios XI <5.11.1 - SQL Injection

Title source: llm

Description

A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php

Exploits (3)

nomisec WORKING POC 1 stars
by sealldeveloper · poc
https://github.com/sealldeveloper/CVE-2023-40931-PoC
nomisec WORKING POC
by G4sp4rCS · poc
https://github.com/G4sp4rCS/CVE-2023-40931-POC
nomisec WORKING POC
by datboi6942 · poc
https://github.com/datboi6942/Nagios-XI-s-CVE-2023-40931-Exploit

Nuclei Templates (1)

Nagios XI v5.11.0 - SQL Injection
MEDIUMVERIFIEDby ritikchaddha
Shodan: title:"Nagios XI"
FOFA: app="nagios-xi"

Scores

CVSS v3 6.5
EPSS 0.8621
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-89
Status published
Products (1)
nagios/nagios_xi 5.11.0 - 5.11.2
Published Sep 19, 2023
Tracked Since Feb 18, 2026