An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can upload files with arbitrary extensions as long as the MIME type corresponds to an image. Therefore it is possible to upload a crafted PHP script to achieve remote command execution.
References
Link | Resource |
---|---|
https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT | Release Notes Vendor Advisory |
https://synacktiv.com | Not Applicable |
https://www.synacktiv.com/sites/default/files/2021-10/Nagios_XI_multiple_vulnerabilities_0.pdf | Exploit Third Party Advisory |
https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT | Release Notes Vendor Advisory |
https://synacktiv.com | Not Applicable |
https://www.synacktiv.com/sites/default/files/2021-10/Nagios_XI_multiple_vulnerabilities_0.pdf | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 06:23
Type | Values Removed | Values Added |
---|---|---|
References | () https://assets.nagios.com/downloads/nagiosxi/CHANGES-5.TXT - Release Notes, Vendor Advisory | |
References | () https://synacktiv.com - Not Applicable | |
References | () https://www.synacktiv.com/sites/default/files/2021-10/Nagios_XI_multiple_vulnerabilities_0.pdf - Exploit, Third Party Advisory |
Information
Published : 2021-10-26 11:15
Updated : 2024-11-21 06:23
NVD link : CVE-2021-40344
Mitre link : CVE-2021-40344
CVE.ORG link : CVE-2021-40344
JSON object : View
Products Affected
nagios
- nagios_xi
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type