CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2021-25296

🔥 Known Exploited (CISA KEV)HIGH
8.8
CVSS Severity Score
EPSS Score59.8790%
EPSS Percentile96.83th
Published2021-02-15
Last Modified2026-07-09
Data SourcesNVDCISA KEVFIRST.org EPSS

Vulnerability Description

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

相關漏洞威脅