Local File Inclusion Vulnerability in Nagios XI Software by Nagios
CVE-2021-37348
7.5HIGH
What is CVE-2021-37348?
Nagios XI versions prior to 5.8.5 contain a local file inclusion vulnerability due to improper validation of pathnames in the index.php file. This flaw may allow an attacker to leverage the vulnerability to include arbitrary files from the server, potentially exposing sensitive information or further compromising the system's integrity.
References
EPSS Score
11% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved