Vulnerability CVE-2023-40933


Published: 2023-09-19   Modified: 2023-09-20

Description:
A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function.

 References:
https://outpost24.com/blog/nagios-xi-vulnerabilities/
http://nagios.com
https://www.nagios.com/products/security/

Copyright 2026, cxsecurity.com

 

Back to Top