CVE-2018-8734: Nagios XI
Critical severity, CVSS 9.8. EPSS: 53.8% chance of exploitation in the next 30 days.
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL commands via the selInfoKey1 parameter.
Affected products
- Nagios Nagios XI: from 5.2.0, before 5.4.13 (fixed in 5.4.13)
Published 2018-04-18. Last modified 2026-06-17.