{ "id": "CVE-2023-40933", "sourceIdentifier": "cve@mitre.org", "published": "2023-09-19T23:15:10.533", "lastModified": "2023-09-19T23:15:10.533", "vulnStatus": "Received", "descriptions": [ { "lang": "en", "value": "A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function." } ], "metrics": {}, "references": [ { "url": "http://nagios.com", "source": "cve@mitre.org" }, { "url": "https://outpost24.com/blog/nagios-xi-vulnerabilities/", "source": "cve@mitre.org" }, { "url": "https://www.nagios.com/products/security/", "source": "cve@mitre.org" } ] }