PT-2025-44469 · Nagios Enterprises · Nagios Xi
Tactifail
·
Published
2025-10-30
·
Updated
2025-10-30
·
CVE-2020-36863
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Nagios XI versions prior to 5.7.2
Description
Nagios XI versions prior to 5.7.2 permit the upload and execution of PHP files within the Audio Import directory. The upload process does not adequately restrict file types or ensure storage outside the webroot, and the web server allows execution within the upload directory. An authenticated attacker with access to the audio import feature can upload a malicious PHP file and then request it, leading to remote code execution with the privileges of the application service.
Recommendations
Update to version 5.7.2 or later.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nagios Xi