CVE-2019-12279
Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form).
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.22%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). NOTE: The vendor disputes this issues as not being a vulnerability because the issue does not seem to be a legitimate SQL Injection. The POC does not show any valid injection that can be done with the variable provided, and while the username value being passed does get used in a SQL query, it is passed through SQL escaping functions when creating the call. The vendor tried re-creating the issue with no luck
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.22% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- nagios/nagios xi
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/153040/Nagios-XI-5.6.1-SQL-Injection.html
- http://www.securityfocus.com/bid/108446
- https://github.com/JameelNabbo/exploits/blob/master/nagiosxi%20username%20sql%20injection.txtExploit, Third Party Advisory
- http://packetstormsecurity.com/files/153040/Nagios-XI-5.6.1-SQL-Injection.html
- http://www.securityfocus.com/bid/108446
- https://github.com/JameelNabbo/exploits/blob/master/nagiosxi%20username%20sql%20injection.txtExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.