VendorsNagiosnagios_xi5.6.9
Vulnerabilities

Nagios Nagios Xi 5.6.9

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2019-20197
In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account.
Published 2019-12-31 · Modified
9.0EPSS 0.224
CVE-2019-20139
In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulereport.php hour or frequency parameter. Any authenticated user can attack the admin user.
Published 2019-12-30 · Modified
5.4EPSS 0.261