Nagios XI SQL Injection Vulnerability in SNMP Trap Interface Edit Page

Vulnerability

A SQL injection vulnerability has been identified in Nagios XI versions prior to 5.7.5. The issue resides in the SNMP Trap Interface edit page, where user input is not properly sanitized, allowing for the injection of malicious SQL commands. Exploitation of this vulnerability requires administrative privileges to access the affected interface. Successfully exploiting this vulnerability could lead to unauthorized disclosure or modification of application data, or execution of arbitrary SQL commands on the backend database.

Impact

Exploitation of this vulnerability allows for SQL injection, which could result in unauthorized data access or modification, and execution of arbitrary SQL commands on the database.

Reproduction

To reproduce this vulnerability, log into Nagios XI with an administrative account. Navigate to the SNMP Trap Interface edit page. Once there, input crafted data that exploits the SQL injection vulnerability by injecting malicious SQL commands into a field that does not properly sanitize user input. After submitting the form, the injected SQL commands could be executed against the backend database, demonstrating the SQL injection vulnerability.

Remediation

Users can upgrade to Nagios XI version 5.7.5 or later, where this vulnerability has been fixed.

Added: Oct 30, 2025, 11:38 PM
Updated: Oct 30, 2025, 11:38 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
5.0
exploitability
5.1
remediation
0.0
relevance
0.9
threat
1.6
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.