PT-2025-31981 · Nagios Enterprises · Graph Explorer+1

Published

2025-08-05

·

Updated

2025-08-05

·

CVE-2012-10029

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 1.3
Description Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection issue in visApi.php. An authenticated user can inject system commands via unsanitized parameters such as host, resulting in remote code execution.
Recommendations Update to Graph Explorer component version 1.3 or later.

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2012-10029

Affected Products

Graph Explorer
Nagios Xi