cve/2023/CVE-2023-40931.md

19 lines
753 B
Markdown
Raw Normal View History

2024-05-28 08:49:17 +00:00
### [CVE-2023-40931](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40931)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/nomi-sec/PoC-in-GitHub
2024-06-10 07:22:43 +00:00
- https://github.com/sealldeveloper/CVE-2023-40931-PoC
2024-05-28 08:49:17 +00:00