CVE-2021-37347

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
13/08/2021
Last modified:
12/07/2022

Description

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because getprofile.sh does not validate the directory name it receives as an argument.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:* 5.8.5 (excluding)


References to Advisories, Solutions, and Tools