CVE-2023-40933: Nagios XI
High severity, CVSS 8.8. EPSS: 3.5% chance of exploitation in the next 30 days.
A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function.
Affected products
- Nagios Nagios XI: before 5.11.2 (fixed in 5.11.2)
Published 2023-09-19. Last modified 2026-07-09.