Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-24401


SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.


Published

2024-02-26T17:15:10.393

Last Modified

2025-06-27T13:23:42.450

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nagios nagios_xi 2024 Yes

References