The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for any other user account.
2021-02-03T22:15:12.063
2024-11-21T05:55:45.733
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nagios | favorites | < 1.0.2 | Yes |
Application | nagios | nagios_xi | 5.8.0 | No |