PT-2025-44472 · Nagios Enterprises · Nagios Xi

Matthew Aberegg

·

Published

2025-10-30

·

Updated

2025-10-30

·

CVE-2020-36869

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 5.7.5
Description Nagios XI versions prior to 5.7.5 have a SQL injection issue in the SNMP Trap Interface edit page. An account with administrative privileges is required to access the affected interface. A user with administrative access can provide crafted input that is not properly sanitized, potentially leading to unauthorized disclosure or modification of application data, or execution of arbitrary SQL commands against the backend database.
Recommendations Update to version 5.7.5 or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-14403
CVE-2020-36869

Affected Products

Nagios Xi