CVE-2020-35578: Nagios XI
High severity, CVSS 7.2. EPSS: 81.9% chance of exploitation in the next 30 days.
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature is mishandled during a plugin upload, a remote, authenticated admin user can execute operating-system commands.
Affected products
- Nagios Nagios XI: before 5.8.0 (fixed in 5.8.0)
Published 2021-01-13. Last modified 2026-06-17.