CVE-2020-36867 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF download/export functionality. User-supplied values used in the PD…
High CVSS: 8.7

CVE-2020-36867

Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF download/export functionality. User-supplied values used in the PDF generation pipeline or the wrapper that invokes offline/pdf helper utilities were insufficiently validated or improperly escaped, allowing an authenticated attacker who can trigger PDF exports to inject shell metacharacters or arguments.
Vendor
Nagios
Product
Nagios Xi
CWE
CWE-78
Yayın Tarihi
2025-10-30 22:15:39
Güncelleme
2025-11-05 18:23:27
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar