
CVE-2020-28900 – Nagios XI / Fusion Privilege Escalation / Cross Site Scripting / Code Execution
https://notcve.org/view.php?id=CVE-2020-28900
24 May 2021 — Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh. Una Comprobación Insuficiente de la Autenticidad de los Datos en Nagios Fusion versiones 4.1.8 y anteriores y Nagios XI versiones 5.7.5 y anteriores, permite la ampliación de privilegios o una ejecución de código como root por medio de vectores relacionados co... • https://packetstorm.news/files/id/162783 • CWE-345: Insufficient Verification of Data Authenticity •

CVE-2021-3273
https://notcve.org/view.php?id=CVE-2021-3273
25 Feb 2021 — Nagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component. To exploit this vulnerability, someone must have an admin user account in Nagios XI's web system. Nagios XI versiones por debajo de 5.7, está afectado por una inyección de código en el componente /nagiosxi/admin/graphtemplates.php. Para explotar esta vulnerabilidad, alguien debe tener una cuenta de usuario administrador en el sistema web de Nagios XI • https://gist.github.com/leommxj/93edce6f8572cefe79a3d7da4389374e • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2020-24899
https://notcve.org/view.php?id=CVE-2020-24899
15 Feb 2021 — Nagios XI 5.7.2 is affected by a remote code execution (RCE) vulnerability. An authenticated user can inject additional commands into normal webapp query. Nagios XI versión 5.7.2, está afectado por una vulnerabilidad de ejecución de código remota (RCE). Un usuario autenticado puede inyectar comandos adicionales en la consulta webapp normal • https://code610.blogspot.com/2020/08/postauth-rce-in-nagios-572.html • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2020-22427
https://notcve.org/view.php?id=CVE-2020-22427
15 Feb 2021 — NagiosXI 5.6.11 is affected by a remote code execution (RCE) vulnerability. An authenticated nagiosadmin user can inject additional commands into a request. NOTE: the vendor disputes whether the CVE and its references are actionable because all technical details are omitted, and the only option is to pay for a subscription service where technical details may be disclosed at an unspecified later time ** EN DISPUTA ** NagiosXI versión 5.6.11, está afectado por una vulnerabilidad de ejecución de código remota ... • https://code610.blogspot.com/2020/03/postauth-rce-bugs-in-nagiosxi-5611.html •

CVE-2021-25299 – Nagios XI 5.7.5 Remote Code Execution
https://notcve.org/view.php?id=CVE-2021-25299
15 Feb 2021 — Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal his/her session cookies or it can be chained with the previous bugs to get one-click remote command execution (RCE) on the Nagios XI server. Nagios XI versión xi-5.7.5, esta afectada por una vulnerabilidad de tipo cross-site scr... • https://packetstorm.news/files/id/161561 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-25296 – Nagios XI OS Command Injection
https://notcve.org/view.php?id=CVE-2021-25296
15 Feb 2021 — Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server. Nagios XI versión xi-5.7.5, esta afectada por una inyección de comandos del Sistema Operativo. La vulnerabilidad se presenta en el archivo /usr/local/nagiosxi/html/includ... • https://packetstorm.news/files/id/170924 •

CVE-2021-25297 – Nagios XI OS Command Injection
https://notcve.org/view.php?id=CVE-2021-25297
15 Feb 2021 — Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server. Nagios XI versión xi-5.7.5, esta afectada por una inyección de comandos del Sistema Operativo. La vulnerabilidad se presenta en el archivo /usr/local/nagiosxi/html/includes/confi... • https://packetstorm.news/files/id/170924 •

CVE-2021-25298 – Nagios XI OS Command Injection
https://notcve.org/view.php?id=CVE-2021-25298
15 Feb 2021 — Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server. Nagios XI versión xi-5.7.5, esta afectada por una inyección de comandos del Sistema Operativo. La vulnerabilidad se presenta en el archivo /usr/local/nagiosxi/html/includes/c... • https://packetstorm.news/files/id/170924 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2021-26024
https://notcve.org/view.php?id=CVE-2021-26024
03 Feb 2021 — The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for any other user account. El plugin Favorites versiones anteriores a 1.0.2 para Nagios XI versión 5.8.0, es vulnerable a una Referencia Directa a Objetos No Segura: es posible crear favoritos para cualquier otra cuenta de usuario • https://www.nagios.com/products/security • CWE-639: Authorization Bypass Through User-Controlled Key •

CVE-2021-26023
https://notcve.org/view.php?id=CVE-2021-26023
03 Feb 2021 — The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS. El plugin Favorites versiones anteriores a 1.0.2 para Nagios XI versión 5.8.0, es vulnerable a un ataque de tipo XSS • https://www.nagios.com/products/security • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •