Security Advisory

CVE-2018-10553

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-04-30 03:00:00
Last updated 2024-08-05 07:39:07
Assigner mitre
State PUBLISHED

Description

An issue was discovered in Nagios XI 5.4.13. A registered user is able to use directory traversal to read local files, as demonstrated by URIs beginning with index.php?xiwindow=./ and config/?xiwindow=../ substrings.