Nagios XI Network Monitor
cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*
- < 1.3
This vulnerability is being actively exploited in the wild.
A command injection vulnerability has been identified in the Graph Explorer component of Nagios XI Network Monitor, in versions prior to 1.3. This vulnerability allows authenticated users to inject system commands through unsanitized parameters, such as 'host', in 'visApi.php', leading to remote code execution.
Exploitation of this vulnerability allows for authenticated users to execute arbitrary system commands on the server where Nagios XI is running, potentially leading to unauthorized access or control over the system.
To reproduce this vulnerability, an authenticated user must log into Nagios XI and navigate to the Graph Explorer component. Once there, the user can inject commands into the 'host' parameter of 'visApi.php'. This injection is possible because the parameter does not properly sanitize user input. After injecting a command, the execution of that command on the server can be observed, demonstrating the successful exploitation of the vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.