SQL Injection Vulnerability in Nagios XI Core Config Manager
CVE-2021-47693
8.7HIGH
What is CVE-2021-47693?
The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.3 and Nagios XI 5.8.5 is susceptible to a SQL injection vulnerability. This exploit stems from inadequate sanitization of user-supplied input in search text handling, allowing authenticated users to inject SQL fragments into configuration object editors. If exploited, this vulnerability can lead to unauthorized access and modification of sensitive configuration and application data. Moreover, in some scenarios, it may facilitate further compromises of both the application and its backend database, making it crucial for users to update to the latest version to mitigate this risk.
Affected Version(s)
XI 0 < 5.8.5
