CVE-2023-40931 | Nagios XI 5.11.0/5.11.1 POST Request banner_message-ajaxhelper.php ID sql injection
A vulnerability labeled as critical has been found in Nagios XI 5.11.0/5.11.1. This affects an unknown function of the file /nagiosxi/admin/banner_message-ajaxhelper.php of the component POST Request Handler. Such manipulation of the argument ID leads to sql injection.
This vulnerability is traded as CVE-2023-40931. Access to the local network is required for this attack to succeed. There is no exploit available.