CVE-2024-24401

CRITICAL

Nagios XI - SQL Injection

Title source: rule

Description

SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.

Exploits (2)

nomisec WORKING POC 36 stars
by MAWK0235 · poc
https://github.com/MAWK0235/CVE-2024-24401
nomisec WORKING POC
by JIBEG-UNIX · poc
https://github.com/JIBEG-UNIX/CVE-2024-24401

Scores

CVSS v3 9.8
EPSS 0.5797
EPSS Percentile 98.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
nagios/nagios_xi 2024 r1.0.1
Published Feb 26, 2024
Tracked Since Feb 18, 2026