Security Advisory
CVE-2020-15901
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsubsys.