VulnerabilityModified
CVE-2021-37350
Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation.
CRITICAL 9.8EPSS 79.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 79.3%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 79.25% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- nagios/nagios xi
- Source
- cve@mitre.org
References
- https://www.nagios.com/downloads/nagios-xi/change-log/Release Notes, Vendor Advisory
- https://www.nagios.com/downloads/nagios-xi/change-log/Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.