PT-2025-44538 · Nagios · Nagios Xi

Published

2025-10-30

·

Updated

2025-10-30

·

CVE-2016-15050

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 5.2.4
Description An issue exists in the notification search functionality where user-supplied search parameters are incorporated into SQL statements without adequate parameterization or sanitation. This allows an authenticated user to manipulate database queries, which could lead to the disclosure or modification of notification data and potentially impact the application database more broadly. SQL injection is a technique where an attacker inserts malicious SQL code into a query to manipulate the database.
Recommendations Update to version 5.2.4 or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2016-15050

Affected Products

Nagios Xi