CVE-2020-5796

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/11/2020
Last modified:
24/11/2020

Description

Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the permissions of files, resulting in low-privileged users being able to write to and execute arbitrary PHP code with root privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nagios:nagios_xi:5.7.4:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools