SQL Injection Vulnerability in Nagios XI Core Config Manager
CVE-2021-47693
What is CVE-2021-47693?
The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.3 and Nagios XI 5.8.5 is susceptible to a SQL injection vulnerability. This exploit stems from inadequate sanitization of user-supplied input in search text handling, allowing authenticated users to inject SQL fragments into configuration object editors. If exploited, this vulnerability can lead to unauthorized access and modification of sensitive configuration and application data. Moreover, in some scenarios, it may facilitate further compromises of both the application and its backend database, making it crucial for users to update to the latest version to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
XI 0 < 5.8.5
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
