Back
CVE-2018-8734
CRITICAL
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL commands via the selInfoKey1 parameter.
Published: Apr 18, 2018
Modified: Jun 17, 2026
CWE-89
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| nagios | nagios_xi | * ≥ 5.2.0 < 5.4.13 |
GitHub Security Advisory GHSA-r9pv-w7cx-x2rm
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5...
References (12)
- https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT Release Notes, Vendor Advisory
- https://blog.redactedsec.net/exploits/2018/04/26/nagios.html Exploit, Technical Description, Third Party Advisory
- https://gist.github.com/caleBot/f0a93b5a98574393e0139104eacc2d0f Third Party Advisory
- https://www.exploit-db.com/exploits/44560/ Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/44969/ Exploit, Third Party Advisory, VDB Entry
- https://www.nagios.com/downloads/nagios-xi/change-log/ Release Notes, Vendor Advisory
- https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT Release Notes, Vendor Advisory
- https://blog.redactedsec.net/exploits/2018/04/26/nagios.html Exploit, Technical Description, Third Party Advisory
- https://gist.github.com/caleBot/f0a93b5a98574393e0139104eacc2d0f Third Party Advisory
- https://www.exploit-db.com/exploits/44560/ Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/44969/ Exploit, Third Party Advisory, VDB Entry
- https://www.nagios.com/downloads/nagios-xi/change-log/ Release Notes, Vendor Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
53.25%
Top 1% most likely to be exploited
Threat Score
55.2 / 100
Data Sources
NVD
EPSS
GitHub