← back
CVE-2023-40931

CVE-2023-40931

23Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 11%
exploitation probability
11%top 4% of all CVEs
observed exploitation
nono source reports it
A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php
Affected products
n/a · n/a