CVE-2021-25297 | Nagios XI 5.7.5 HTTP Request switch.inc.php os command injection
A vulnerability was found in Nagios XI 5.7.5. It has been declared as critical. This vulnerability affects unknown code of the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php of the component HTTP Request Handler. The manipulation leads to os command injection.
This vulnerability was named CVE-2021-25297. The attack can only be done within the local network. Furthermore, there is an exploit available.