CyberSec.Space Logo
返回 CVE 浏览器

CVE-2021-25298

🔥 Known Exploited (CISA KEV)HIGH
8.8
CVSS Severity Score
EPSS Score60.1000%
EPSS Percentile94.51th
Published2021-02-15
Last Modified2026-07-09
Data SourcesNVDCISA KEVFIRST.org EPSS

Vulnerability Description

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

相关漏洞威胁