CVE-2023-40933
HIGHNagios XI < 5.11.2 - Authenticated SQL Injection via ID Parameter in update_banner_message()
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-40933. PoCs published by sealldeveloper.
AI-analyzed exploit summary This repository provides a functional sqlmap payload to exploit CVE-2023-40933, an SQL injection vulnerability in Nagios XI. The exploit leverages an authenticated session to dump the 'xi_users' table via a crafted request to the banner_message-ajaxhelper.php endpoint.
Description
A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function.
Exploits (1)
This repository provides a functional sqlmap payload to exploit CVE-2023-40933, an SQL injection vulnerability in Nagios XI. The exploit leverages an authenticated session to dump the 'xi_users' table via a crafted request to the banner_message-ajaxhelper.php endpoint.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H