Nagios XI SQL Injection Vulnerability in Notification Search

Vulnerability

A SQL injection vulnerability has been identified in Nagios XI versions prior to 5.2.4. This vulnerability resides in the notification search feature, where user-provided search parameters were directly included in SQL queries without proper sanitization or parameterization. As a result, an authenticated user could manipulate database queries, potentially leading to unauthorized disclosure or modification of notification data. In some cases, this exploitation could have broader implications for the application's database.

Impact

Exploitation of this vulnerability allows for SQL injection, which could be used to manipulate database queries and potentially access or modify sensitive data.

Reproduction

To reproduce this vulnerability, an authenticated user can enter crafted search parameters into the notification search feature. The lack of proper input validation will allow these parameters to be executed as part of the SQL query, leading to unauthorized data access or manipulation.

Remediation

Users can upgrade to Nagios XI version 5.2.4 or later, where this vulnerability has been fixed.

Added: Oct 31, 2025, 12:06 AM
Updated: Oct 31, 2025, 12:06 AM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
5.0
exploitability
5.6
remediation
0.0
relevance
0.8
threat
1.6
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.