CVE-2021-47700
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
30/10/2025
Last modified:
05/11/2025
Description
Nagios XI versions prior to 5.8.7 used a temporary directory for Highcharts exports with overly permissive ownership/permissions under the Apache user. Local or co-hosted processes could read/overwrite export artifacts or manipulate paths, risking disclosure or tampering and potential code execution depending on deployment.
Impact
Base Score 4.0
8.50
Severity 4.0
HIGH
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:* | 5.8.7 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



