Privilege Escalation Vulnerability in Nagios XI by Nagios Enterprises
CVE-2020-36868 
8.5HIGH
What is CVE-2020-36868?
Nagios XI versions before 5.7.3 contain a vulnerability in the getprofile.sh script that could allow a local attacker to escalate their privileges. Due to insecure handling of files and insufficient validation of user inputs, this vulnerability could be exploited to execute arbitrary commands or manipulate privileged files, especially as the script is often run with elevated privileges. Organizations using affected versions are urged to upgrade to mitigate potential security risks.
Affected Version(s)
XI 0 < 5.7.3
