CVE-2020-28911: Nagios Fusion
Medium severity, CVSS 6.5. EPSS: 3.6% chance of exploitation in the next 30 days.
Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwords used to manage fused servers via the test_server command in ajaxhelper.php.
Affected products
- Nagios Fusion: up to and including 4.1.8
Published 2021-05-24. Last modified 2026-06-17.