SQL Injection Vulnerability in Nagios XI Core Config Manager
CVE-2021-47693

8.7HIGH

Key Information:

Vendor

NagiOS

Status
Vendor
CVE Published:
30 October 2025

What is CVE-2021-47693?

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.3 and Nagios XI 5.8.5 is susceptible to a SQL injection vulnerability. This exploit stems from inadequate sanitization of user-supplied input in search text handling, allowing authenticated users to inject SQL fragments into configuration object editors. If exploited, this vulnerability can lead to unauthorized access and modification of sensitive configuration and application data. Moreover, in some scenarios, it may facilitate further compromises of both the application and its backend database, making it crucial for users to update to the latest version to mitigate this risk.

Affected Version(s)

XI 0 < 5.8.5

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-47693 : SQL Injection Vulnerability in Nagios XI Core Config Manager