← Back to CVE List

CVE-2021-25297

Published: 2021-02-15T13:15Z
Last Modified: 2025-03-14T17:07Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt