CVE-2018-10553

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
30/04/2018
Last modified:
07/06/2018

Description

An issue was discovered in Nagios XI 5.4.13. A registered user is able to use directory traversal to read local files, as demonstrated by URIs beginning with index.php?xiwindow=./ and config/?xiwindow=../ substrings.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nagios:nagios_xi:5.4.13:*:*:*:*:*:*:*