PoC Index

CVE-2018-8733

CRITICAL 9.8EPSS 27.0%

Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability.

CVSS v3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
27.01% chance of exploitation in the next 30 days, 98th percentile
Published
2018-04-18
Updated
2024-08-05

Metasploit modules (1)

ExploitDB entries (2)

References

Related