SQL Injection Vulnerabilities in Nagios XI by Nagios
CVE-2020-36859
What is CVE-2020-36859?
The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.7 and Nagios XI 5.7.4 is susceptible to multiple SQL injection vulnerabilities in the object edit pages. This security flaw arises from unsanitized user-supplied input being embedded into SQL queries utilized by the configuration object editors. Authenticated users could exploit these vulnerabilities to inject SQL fragments, potentially leading to unauthorized disclosure or alteration of configuration and application data. In certain circumstances, this could also allow for further threats to the application or the backend database.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
XI 0 < 5.7.4
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
