CVE-2023-40931
Nagios XI v5.11.0 - SQL Injection
Record summary
CVE-2023-40931 has a selected CVSS score of 6.5 (medium); EIP currently links 3 repository PoCs and 1 Nuclei template.
Description
A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php
Exploitation context
Proofs of concept
3Repository PoCs
GitHubsealldeveloper/CVE-2023-40931-PoCRepository PoCby sealldeveloperStars: 1Not analyzed1 file
GitHubdatboi6942/Nagios-XI-s-CVE-2023-40931-ExploitRepository PoCby datboi6942Stars: 0Not analyzed1 file
GitHubG4sp4rCS/CVE-2023-40931-POCRepository PoCby G4sp4rCSStars: 0Not analyzed4 files
Nuclei templates
1ProjectDiscoveryMEDIUMNagios XI v5.11.0 - SQL InjectionCVSS 6.5
A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php.
Impact
Successful exploitation of this vulnerability allows an authenticated attackers to execute arbitrary SQL commands.
Remediation
Upgrade Nagios XI to a patched version or apply the vendor-supplied patch to mitigate this vulnerability.
Source: ProjectDiscovery