Command Injection Vulnerability in Nagios Fusion by Nagios
CVE-2020-28902
9.8CRITICAL
What is CVE-2020-28902?
A command injection vulnerability in Nagios Fusion version 4.1.8 and earlier can be exploited to escalate privileges from the apache user to root through the cmd_subsys.php file. This flaw exposes the system to potential takeover by allowing unauthorized commands to be executed with elevated privileges, leading to severe security risks for affected installations.